07-26-2002 04:07 AM - edited 03-08-2019 11:42 PM
Hello,
We are planning to make ISP connection redundant.
We wil have two routers for the Internet access.
Question 1:
Can one sensor shun two routers at a time, and how to do it ?
Have we only to add the two lines in managed.conf as follows ?
NetDevice ROUTER1_IP Cisco ROUTER1_PASSWORD
ROUTER1_ENABLE_PASSWORD
NetDevice ROUTER2_IP Cisco ROUTER2_PASSWORD
ROUTER2_ENABLE_PASSWORD
Q2:
What kind of CIsco routers and version of IOS can IDS Sensor
shun ?
Thank you.
Daiichiro Beppu
NTT DATA SECURITY
Japan
07-29-2002 05:37 AM
Yes, you can configure IDS to shun two routers.
Any version on Cisco router should do. IDS is not IOS version dependant.
HTH
R/Yusuf
07-29-2002 08:05 AM
The only IDS restrictions on IOS versions are that the version should
be Y2K compliant and it should support named ACLs. Any Cisco router
running IOS version 11.2 or greater will work with IDS.
If you update managed.conf to support more than one
router, you will need to add 1 NetDevice entry for the router and at
least 1 ShunInterfaceCisco entry for the interface(s) the sensor will
be shunning on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide