Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IDS not functioning. No events generated in IEV

Hello all,

I did a simple setup in my LAB. IDS version is 3.1. I placed my sensor in 192.168.1.100 address and one more machine as my IEV host. I installed IEV in that machine which is the event destination. I got my connection established to the sensor. In the event view i got "route up " alarm. Thought my connecion is complete i could not get any alarm apart from route up and route down(because i tried moving my monitoring interface cable). I tried adding the internal network in the idm manager , but stil its not detecting any kinds of attack. I tried lots of IIS exploit attacks and ICMP flood attack. What am i missing ?

I checked the status of the sensor and the process its running..tried restarting the sensor.. it did not help

Thanks in advance

Sen

1 REPLY
Cisco Employee

Re: IDS not functioning. No events generated in IEV

How do you initially configure the sensor?

If you run nrconns is there a process nr.packetd running?

If nr.packetd is running then check and see if any alarms are being generated in the /usr/nr/var/log.* file.

If nr.packetd is not running then keep reading below:

When configuring the sensor you use sysconfig-sensor.

Option 6 is for setting up the communication parameters.

During option 6 you will be asked the following question:

"Will IDM (WEB based Intrusion Detection Device Manager) be used

to configure the sensor (y/n)"

Answering "n" to this question prompts you for the IDS managers hostid, orgid, etc, BUT will not start nr.packetd. The IDS manager will have to push a new configuration which starts nr.packetd. The only IDS managers that can do this are CSPM, Unix Director, and IDS MC. If you are using IEV and configuring with IDM then do not answer "n" to this question.

Answering "y" to this question will start up nr.packetd. This is what you want if using IEV. Then you need to follow the instructions in the user's guide for how to configure the sensor THROUGH IDM to talk with the IEV.

I would recommend following the steps from the following link:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13872_01.htm#xtocid5

These steps are the ones that describe how to add IEV through IDM instead of incorrectly through sysconfig-sensor:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13872_01.htm#xtocid12

Marco

226
Views
0
Helpful
1
Replies
CreatePlease login to create content