cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
511
Views
0
Helpful
8
Replies

How to find out the type of hardware?

j.warrier
Level 1
Level 1

Hi,

On an IDS sensor, using command line, how do we find out what kind of a box are we on? I can find out the OS, but the hardware model of the appliance?

Also, does the event virewer and IDS sensor forget each other after a period of inactivity. I find that if the Post Office Protocol is down for a period of time, they lose each others configuration. Do they rediscover each other automatically?

jwarrier

8 Replies 8

kleem
Cisco Employee
Cisco Employee

With the release of CIDS 4.0, you can use the CLI "show version' command to identify the model. There is no similar command in earlier versions of the software.

The IEV and Sensor connection should remain active as long as there is a network connection. Should there be a network disruption, the devices automatically reconnect after the network connection is restored.

Thanks!

I expected the devices to rediscover after the network comes up, but they do not. In this case the network disruption was for a few hours 6-7 hours. Is there a parameter to be tuned (like history or something) which will make them keep their configs even after prolonged disconnections.

In IEV3.1, the postoffice is supposed to automatically reconnect to the sensor when the network is up again. If not, can you open the Device Status window ( right click the device name and choose "Device Status" menu) and let us know the information inside that window?

Besides, since postoffice didn't auto connect to sensor after the network disruption, did you try to remove the device from IEV and then add it again to make them communicate? or some other mechanism you use?

Thanks,

Jie

Hi Jie,

When I tried to add the device after removing it, there was no problem reconnecting. Otherewise it does not estrablish communication automatically. The status is something like, 'syn sent and but none received'.

Can you ping the Sensor from the IEV host when you see the 'syn sent and but none received' msg? Can the Sensor ping the IEV host? What does the sensor report when you use the 'nrconns' command?

Ya, I can ping both ways.nrconns shows a blank line without any status indication, whereas I was expecting an 'established' status. nrstatus shows all the services are running. Log files show that packet capture is happening.

Please send me the output of the IDM diagnostics (zipped please).

Thanks, kleem@cisco.com

Thanks . I am sorry, I have reconfigured the EV and Sensor, to get it up and running. Let me see if I can simulate the problem again at a suitable time to send you the logs.