cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
500
Views
5
Helpful
3
Replies

pointing IPS/IDS sensors to a 3rd party

Brent Rockburn
Level 2
Level 2

Hey guys, this is probably a simple question but for some reason I can't find a simple answer.

I'm testing out a Juniper STRM 2500 box and need to point my 4 IDS/IPS sensors to it so it can collect the data and so on. Is there a command to forward events onto the 3rd party device or do I simply set the logging (syslog type) to send to the juniper box.

Thanks in advance.

3 Replies 3

rhermes
Level 7
Level 7

Unless the Juniper STRM can act as an SDEE client (some SIMs can), you'll have to enable the SNMP action on each signature you wish to have report and point your SNMP traps at the Juniper STRM IP address.

The STRM Juniper box does do SDEE but how do you configure SDEE on the 4215 sensor? It does give the option for a 3rd party interface but it seems more like it wants to receive information and not send it. Any tips would help.

The sensor is an SDEE server, configure the sensor to allow the STRM's IP address and give the sensor login/password to your STRM box and let STRM connect to the sensor.

The STRM box will have to request the event data from the sensor.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card