Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Ficha de datos Pagina 85

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 168
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 84
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 85 -
Answer: B
Cisco Courseware 13-41
QUESTION NO: 3
Which type of signature can be configured to alarm only on specific source or
destination IP addresses?
A. atomic signatures
B. flood signatures
C. service signatures
D. state signatures
ANSWER: A
The task is simple, the simplest engine should do.
Page 13-29 CIDS Courseware v4.0
QUESTION NO: 4
A Cisco IDS Sensor is capturing large volumes of network traffic. Which Cisco IDS
Sensor status alarm is an indication that the Sensor is being overwhelmed?
A. Daemon down
B. Route down
C. No traffic
D. Captured packet count
E. Missed packet count
F. Network saturated
Answer: E
Explanation: Problem: sensorApp does not respond after hours of being seriously
oversubscribed. All system memory, including SWAP, is exhausted when a 700 Mbps traffic
feed is sent to the 250 Mbps appliance 4235 over several hours.
Symptom: The CLI show version command may say "AnalysisEngine Not Running" or
control transactions will timeout with error about sensorApp not responding. You will see 993
missed packet alarms before the unresponsive state (if that alarm is Enabled).
Workaround: 1) Do not seriously oversubscribe the sensor. Chose the right appliance for your
network segment and partition the traffic accordingly. 2) If sensorApp (aka AnalysisEngine)
is listed as Not Running or is not responsive, issue a RESET command on the CLI. Do this
after examining the traffic feed and adjusting the feed to the sensor so it is within the rating
for the specific appliance
http://www.cisco.com/en/US/partner/products/sw/secursw/ps2113/prod_release_note09186a0
0801a00ac.html
Vista de pagina 84
1 2 ... 80 81 82 83 84 85 86 87 88 89 90 ... 167 168

Comentarios a estos manuales

Sin comentarios