Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

MY threat response dosn't work well!!

i hva an ids 4235(IOS V 4.1); i instaled in server machine Threat response for managing the logs and alarms. i did keep the intiale config of threat response. and for test i activate all icmp sig, but when i ping to my prtected zone. tje alarmes are not whown.

my sniffing interface is plugged in swtich not in a hub. (must i do the merroring or it work witout)

please, i'm waiting

thinks a lot

4 REPLIES
Cisco Employee

Re: MY threat response dosn't work well!!

If the sniffing interface is plugged into a switch then you need to set that switch port up as a SPAN port, otherwise it won't see any of the ping traffic (or any traffic other than broadcasts for that matter).

New Member

Re: MY threat response dosn't work well!!

OK, my switch dos not has this port feature, but can use the merroring in setead of SPAN Port?

New Member

Re: MY threat response dosn't work well!!

The idea is to send all traffic you want to monitor to the port that the IDS connected to on the switch. You will have to check with the documentation of your switch. If mirroring does that then yes it will work. What is the make of your switch?

New Member

Re: MY threat response dosn't work well!!

OK, my product is made by planet

101
Views
0
Helpful
4
Replies
CreatePlease to create content