Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IDSM2 support in 6509 with native IOS?

Does a Cat 6509 running current native IOS support the IDSM2?

I have an IDSM2 blade in a 6509 and have been using it under CatOS 7.6.1. Yesterday, I upgraded from a Sup II to a Sup 720, and converted to native IOS 12.2(14)SX1. The release notes for this IOS claim to support the IDSM, and it's the latest IOS available, AFAIK.

Show mod recognizes the IDSM2 in slot 6. However, session 6 says invalid command. Sho interface does not show any 6/x ports, although an SNMPwalk does show the correct 8 ports.

Doing a conf t on Int Gig 6/1-6/8 yields the message "This interface cannot be modified". This is a different messages than given for a non-existant port.

Without being able to assign a VLAN to to the comm port (6/2), and without being able to session to the blade, I'm stuck. Any ideas?

/Chris Thomas, UCLA

New Member

Re: IDSM2 support in 6509 with native IOS?

I figured out a little:

The syntax of session is SESSION SLOT 6 PROC 1. That seems to work.

There is a SHOW INTRUSION-DETECTION cmd and INTRUSION-DETECTION option when in CONF T mode. I figured out how to set the management port to the correct vlan, but I've not been able to figure out how to do the equivalent of SPAN under CatOS.

Can anyone tell me where the above commands are documented? I've searched CCO and can't find anything about them.

New Member

Re: IDSM2 support in 6509 with native IOS?

The following commands are sufficient to minimally configure the IDSM-2 under IOS 12.2(14)SX1 (Sup720)

intrusion-detection module 6 management-port access-vlan 123

monitor session 1 source interface Gi2/16

monitor session 1 destination intrusion-detection-module 6 data-port 1

monitor session 2 source interface Gi3/16

monitor session 2 destination intrusion-detection-module 6 data-port 2

I'm using both data ports because the 6500 has a limit of one tx source per monitor session and I have two ISP connections.

There are configuration commands to configure VLANs on the data ports, but I have been unable to locate any documentation. The default seems to imply that the data ports are down, but they seem to work. I also can't find anything about configuring the TCP reset port.

Cisco Employee

Re: IDSM2 support in 6509 with native IOS?

This is all documented in the version 4.1 User's Guide:

Under each section the commands for both traditional Cat OS and Native IOS are provided.