Solutions Fast Track Understanding the Cisco IDS Management Center


Solutions Fast Track

Understanding the Cisco IDS Management Center

*

The IDS MC logs centralized analysis annal pertinent to the advance apprehension system.

*

The IDS MC can administer about 300 sensors.

*

Sensor and signature agreement are key functions performed by the IDS MC.

*

Maintaining accepted sensor software and signature releases are functions of the IDS MC.

Installing the Cisco IDS Management Center

*

Prerequisite articles accommodate Windows 2000 and Cisco Works Common Services.

*

A accompanying artefact is the Aegis Monitor that displays real-time alarms from the sensors.

Setting Up Sensors and Sensor Groups

*

Sensors should be placed at access credibility to the arrangement and amid sub-networks of altered aegis levels.

*

Sensors with agnate agreement settings can be placed in the aforementioned sensor accumulation or subgroup.

*

A sensor can be placed abaft a clarification router so the sensor can affair a blocking command to the router back an advance is detected.

Configuring Signatures and Alarms

*

There are six classifications of signatures: general, TCP, UDP, string-matching, ACL, and custom.

*

Signature settings can be configured and acquainted by the IDS MC.

*

The IDS MC can generate, approve, and arrange sensor agreement files.

Configuring Reports

*

The IDS MC has six analysis log reports: subsystem, sensor adaptation import, sensor agreement import, sensor agreement deployment, animate notification, and analysis log.

*

Letters can be generated immediately, appointed at a after time, or appointed at approved intervals.

*

The generated letters can abide online for examination or be deleted.

*

The generated letters can be exported into an HTML file.

*

The appointed address ambit can be edited.

Administering the Cisco IDS MC Server

*

Database Rules are advised to activate accomplishments back defined database accident thresholds are reached.

*

The IDS MC can be acclimated to amend sensor software versions and signature releases.

*

An e-mail server can be defined for the IDS MC to use to administer e-mail notifications.