cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
349
Views
0
Helpful
1
Replies

IDS Newbie

Billy Dodson
Level 1
Level 1

I have been thrown into this IDS thing as of a few days ago and I am not sure where to start. I have read some documentation on the site but it all referes to a CLI. The IDS we have is running redhat linux which is not the same CLI that the documentation refers too. Is there any documents out there that refer to the version I am on, or is there a way to find the version that it is running?

1 Reply 1

a.arndt
Level 3
Level 3

It sounds like you have a sensor running at least version 4.0 to me.

Here's a link where you can find Installation and Configuration guides for everything Cisco IDS:

http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_installation_and_configuration_guides_list.html

In order to interact with the sensor using something other than CLI, you’ll have to initialize it first using the CLI. The docs at the above link will get you started, including using IDM, IEV and VMS Basic.

BTW, whether you have a box running 4.0 or 4.1, checking the version is the same. Login using the default account (username is 'cisco' [no quotes], password is the same). Once logged in, issue the command 'show version' and you'll see some output similar to this:

Application Partition:

Cisco Systems Intrusion Detection Sensor, Version 4.1(4)S99

OS Version 2.4.18-5smpbigphys

Platform: IDS-4235

Using 623529984 out of 921522176 bytes of available memory (67% usage)

Using 834M out of 15G bytes of available disk space (6% usage)

MainApp 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

AnalysisEngine 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

Authentication 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

Logger 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

NetworkAccess 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

TransactionSource 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

WebServer 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500 Running

CLI 2004_Apr_15_15.03 (Release) 2004-04-15T15:11:59-0500

Upgrade History:

* IDS-sig-4.1-4-S98 11:18:22 UTC Tue Jun 22 2004

IDS-sig-4.1-4-S99.rpm.pkg 11:35:59 UTC Mon Jun 28 2004

Recovery Partition Version 1.1 - 4.0(1)S37

Hope this helps (rate the post if it does),

Alex Arndt