
10-4 Cisco Secure Intrusion Detection System 2.1Lab 10.9.1 Copyright 2001, Cisco Systems, Inc.
switch#(enable) commit security acl SPAN_PVLAN
(where PVLAN = 300 + pod number)
Step 6 Map the VACL to the VLAN:
switch#(enable) set security acl map SPAN_PVLAN PVLAN
(where PVLAN = 300 + pod number)
Note The destination capture port is assigned by default to IDSM Port 1.
Task 3—Verify the switch and IDSM Configuration
Perform the following lab steps to verify the switch and IDSM configurations are
correct.
Step 1 Display your switch’s IDSM configuration:
switch>(enable) show config M
(where M = module number assigned)
switch> (enable) show conf 3
This command shows non-default configurations only.
Use 'show config <mod> all' to show both default and non-default configurations.
..............
begin
!
# ***** NON-DEFAULT CONFIGURATION *****
!
!#time: Sat Nov 25 2000, 02:55:48
!
# default port status is enable
!
!
#module 3 : 2-port Intrusion Detection System
set port gvrp 3/2 disable
set security acl capture-ports 3/1
end
Step 2 Display the switch’s security ACL settings:
switch>(enable)show security acl
ACL Type VLANS
-------------------------------- ---- -----
SPAN_301 IP 301
switch>(enable)show security acl map PVLAN
(where PVLAN = 300 + pod number)
switch>(enable)show security acl map 301
VLAN 301 is mapped to IP ACL SPAN_301.
Step 3 Session into your IDS module and display the IDSM configuration:
idsm# show configuration
Using 46178304 out of 267702272 bytes of available memory
!
Using 460935168 out of 4211310592 bytes of available disk space
!
Comentarios a estos manuales