cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
434
Views
0
Helpful
3
Replies

IDSM troubleshooting

aksher
Level 1
Level 1

How to diagnose whether the IDSM is monitoring traffic. What are the steps.

3 Replies 3

rhermes
Level 7
Level 7

Check that the IDSM-2 is getting traffic. On the CLI do a "show interface"

Check if the traffic is getting to the analysis engine with a "show stat anal"

(if you're not seeing your taffic in the analysis engine, you forgot to add the interface to the virtual sensor)

Then turn on sig 2004 (ICMP echo reply) and run a few pings past the sensor to see if you are getting sigs to fire.

Both the above coands are working fine. How ever I am not geting any alerts on the event viewer.Pls help on this.

Can you post the "show config" of the IDSM and "show run | inc intrusion" of the core switch?

Regards

Farrukh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card