Installing Cisco Intrusion Prevention System Appliances and Modules 5.1
Index

Table Of Contents

Numerics - A - B - C - D - E - F - G - H - I - L - M - N - O - P - R - S - T - U - V - X -

Index

Numerics

4GE bypass interface card

configuration restrictions 6-4

described 6-4

illustration 6-4

A

accelerator cards see XL cards

access control list see ACL

accessing IPS software 11-2

accessories

four-post racks

installing appliances in racks 4-21

installing cable-management arms 4-22

installing slide assemblies 4-19

rack-kit contents 4-19

routing cables 4-26

tools 4-19

IDS-4210 package contents 2-7

IDS-4235/4250 package contents 4-11

two-post racks

center-mount installations 4-29

flush-mount installations 4-30

marking racks 4-29

rack kit contents 4-28

tools 4-28

actions

ACL changes 1-3

IP logs 1-3

multiple packet drop 1-3

TCP reset 1-2

active update bulletin subscription 11-12

AIP-SSM

described 1-15

indicators 7-2

installing 7-3

memory specifications 7-1

models 1-15

removing 7-5

requirements 7-2

show module 1 command 7-4

specifications 7-1

time sources 1-20

verifying status 7-4

appliances

ACLs 1-3

described 1-13

four-post racks

installing appliances in racks 4-21

installing cable-management arms 4-22

routing cables 4-26

hardware

dual serial communication cables 4-8

spare hard-disk drives 4-6

terminal settings 4-8

IDS-4210 indicators 2-2

IDS-4215

rack mounting 3-6

surface mounting 3-5

IDS-4235/4250

front panel 4-3

indicators 4-3

installing

XL cards (IDS-4235/4250) 4-14

XL cards (IDS-4250) 4-14

managers 1-13

models 1-13

restrictions 1-14

setting up a terminal server 1-14

SPAN 1-13

TCP reset 1-2

terminal server 1-14

time sources 1-19

two-post racks

marking racks 4-29

rack kit contents 4-28

tools 4-28

XL cards fiber ports 4-16

ASA described 1-15

attack responses TCP reset actions 1-2

B

back panel features

IDS-4210 2-3

IDS-4215 3-2

IDS-4235/4250 4-4

IPS-4240/4255 5-3

IPS-4260 6-6

BIOS

IDS-4235/4250 upgrading 4-7

C

cable pinouts

console port 1-28

RJ-45 1-28

RJ-45 to DB-25 1-29

RJ-45 to DB-9 1-29

Catalyst software

IDSM-2

enabling full memory tests 8-12

resetting 8-14

Cisco.com

accessing software 11-2

Active Update Bulletins 11-12

downloading software 11-1

IPS software 11-1

software downloads 11-1

Cisco IOS software

IDSM-2

enabling full memory tests 8-13

resetting 8-14

Cisco Security Center

described 11-13

URL 11-13

Cisco Services for IPS

service contract 11-8

supported products 11-8

clear events command 1-22

command and control interfaces

described 1-4

Ethernet 1-2

list 1-4

commands

clear events 1-22

copy license-key 11-10

setup 10-1, 10-2

show module 1 7-4

console port pinouts 1-28

copy license-key command 11-10

correcting time on the sensor 1-22

cryptographic account

Encryption Software Export Distribution Authorization from 11-2

obtaining 11-2

D

DC power supply IPS-4240 5-9

downloading software 11-1

E

electrical safety guidelines 1-24

enabling

full memory tests

Catalyst software 8-12

Cisco IOS software 8-13

Encryption Software Export Distribution Authorization form

cryptographic account 11-2

described 11-2

ESD environment working in 1-25

Ethernet port indicators IPS-4260 6-7

Event Store clearing events 1-22

F

fail-over testing 6-4

front panel indicators

IDS-4210 2-2

IDS-4215 3-2

IDS-4235/4250 4-3

IPS-4240/4255 5-2

IPS-4260 6-6

front panel switches IPS-4260 6-5

G

grounding lugs

IPS-4240/4255 5-6

IPS-4260 6-14

guidelines

electrical safety 1-24

power supplies 1-25

rack configuration 1-23

sites 1-23

H

hardware

four-post racks 4-18

power supply (IDS-4235/4250) 4-12

SCSI hard-disk drives 4-16

spare hard-disk drives 4-6

two-post racks 4-28

hardware bypass

configuration restrictions 6-4

IPS-4260 6-4

with software bypass 6-4

I

IDS-4210

accessories package contents 2-7

back panel features 2-3

bezel

described 2-7

installing 2-7

removing 2-7

center mount brackets

installing 2-8

tools 2-8

front mount brackets

installing 2-10

tools 2-10

front panel

illustration 2-2

indicators 2-2

installing 2-5

IDS-4215

4FE card

installing 3-22

removing 3-20

accessories 3-4

back panel

illustration 3-2

indicators 3-3

back panel features 3-2

BIOS upgrade 3-9

chassis cover

removing 3-11

replacing 3-13

compact flash device

removing 3-17

replacing 3-18

front panel

illustration 3-2

indicators 3-2

hard-disk drive

removing 3-15

replacing 3-16

installing 3-7

rack mounting 3-6

ROMMON upgrade 3-9

specifications 3-3

surface mounting 3-5

upgrading

BIOS 3-9

ROMMON 3-9

IDS-4235

back panel (illustration) 4-4

described 4-1

front panel (illustration) 4-3

upgrading BIOS 4-7

IDS-4235/4250

accessories kit 4-11

back panel features 4-4

bezel

described 4-12

installing 4-12

removing 4-12

front panel indicators 4-3

installing 4-8

installing power supply 4-12

rack mounting (2-post) 4-28

rack mounting (4-post) 4-18

SCSI hard-disk drives installing 4-18

specifications 4-6

IDS-4250

back panel (illustration) 4-4

front panel

illustration 4-3

indicators 4-3

installing 4-8

SCSI hard-disk drives 4-18

SX card 4-14

two hard-disk drives 4-16

XL cards 4-14

SCSI hard-disk drives removing 4-17

upgrading BIOS 4-7

IDS-4250-XL TCP reset interface 4-8

IDS appliances

four-post racks

installing slide assemblies 4-19

rack kit contents 4-19

tools 4-19

hardware

dual serial communication cables 2-5

terminal settings 2-5

two-post racks

center-mount installations 4-29

flush-mount installations 4-30

unsupported models 1-12

IDSM-2

described 1-16

enabling full memory tests

Catalyst software 8-12

Cisco IOS software 8-13

front panel 8-3

hot swapping 8-4, 8-8

installing

procedure 8-5

required tools 8-4

verifying 8-8

PFC 8-5

powering down (Catalyst OS) 8-15

powering down (Cisco IOS) 8-16

powering up (Catalyst OS) 8-15

powering up (Cisco IOS) 8-16

removing 8-10

requirements 8-2

resetting

Catalyst software 8-14

Cisco IOS software 8-14

shutdown

button 8-3

command 8-3

described 8-10

slot assignments 8-5

SPAN 1-16

specifications 8-1

status indicator 8-3

supported configurations 8-2

TCP reset port 8-3

time sources 1-19

VACLs 1-16

verifying installation 8-8

IDS switch modules unsupported models 1-12

indicators IDS-4210 2-2

initialization verifying 10-8

initializing the sensor 10-1, 10-2

inline mode described 1-10

inline VLAN pair mode

described 1-10

supported sensors 1-10

installation preparation 1-22

installer major version described 11-5

installer minor version described 11-5

installing

AIP-SSM 7-3

IDS-4210 2-5

IDS-4215 3-7

IDS-4235 4-8

IPS-4240 5-7

IPS-4260 6-14

license key 11-11

NM-CIDS 9-6

power supply (IDS-4235/4250) 4-12

SCSI hard-disk drives (IDS-4235/4250) 4-18

sensor license 11-9

SX cards (IDS-4250) 4-14

XL cards (IDS04235/4250) 4-14

XL cards (IDS-4235/4250) 4-14

interfaces

command and control 1-4

configuration restrictions 1-8

described 1-3

port numbers 1-3

sensing 1-4

slot numbers 1-3

TCP reset 1-7

interface support (table) 1-5

IPS-4240

accessories 5-5

back panel

illustration 5-3

indicators 5-3

described 5-1

features 5-2

front panel

illustration 5-2

indicators 5-2

installing DC power supply 5-9

rack mounting 5-5

IPS-4240/4255

back panel features 5-3

front panel indicators 5-2

installing 5-7

specifications 5-4

IPS-4255

accessories 5-5

back panel (illustration) 5-3

front panel

illustration 5-2

indicators 5-2

installing 5-7

rack mounting 5-5

IPS-4260

4GE bypass interface card 6-2

accessories kit 6-9

back panel features 6-6

chassis cover removing 6-18

described 6-1

Ethernet port indicators 6-7

features 6-5

front panel indicators 6-6

front panel switches 6-5

grounding lugs 6-14

hardware bypass 6-4

installing 6-14

network ports 6-2

performance 6-2

power supplies 6-2

power supply indicators 6-7

rack mounting (2-post) 6-12

rack mounting (4-post) 6-9

sensing interfaces 6-2

specifications 6-8

supported PCI cards 6-2

IPS-4260 chassis cover replacing 6-18

IPS modules time synchronization 1-21

IPS software

available files 11-1

obtaining 11-1

platform-dependent release examples 11-5

IPS software file names

major updates (illustration) 11-3

minor updates (illustration) 11-3

patch releases (illustration) 11-3

service packs (illustration) 11-3

L

license key installing 11-11

Licensing panel configuring 11-9

logging in terminal servers 1-14

M

major updates described 11-3

minor updates described 11-3

modes

IDS 1-1

inline 1-10

IPS 1-1

modules

AIP-SSM

described 1-15

memory specifications 7-1

specifications 7-1

IDSM-2 1-16, 8-2, 8-3, 8-4, 8-5, 8-10

NM-CIDS 1-17, 9-1, 9-4, 9-5, 9-6, 9-8, 9-9, 9-10, 9-11

N

Network Timing Protocol see NTP

NM-CIDS

blank panels 9-11

described 1-17

front panel 9-4

hardware architecture 9-3

installing

OIR support 9-8

required tools 9-6

interfaces 9-5

OIR support 9-5

removing OIR support 9-10

requirements

hardware 9-3

platforms 9-2

specifications 9-1

status indicators 9-5

time sources 1-18, 1-20

NTP

described 1-19

incorrect configuration 1-21

time synchronization 1-19

understanding 1-19

O

obtaining

cryptographic account 11-2

IPS software 11-1

P

passwords service account 10-2

patch releases described 11-4

PFC described 8-5

Policy Feature Card see PFC

powering down IDSM-2 8-15, 8-16

powering up IDSM-2 8-15, 8-16

power supplies guidelines 1-25

power supply indicators IPS-4260 6-7

preparing for sensor installation 1-22

promiscuous mode

described 1-9

packet flow 1-9

R

rack configuration guidelines 1-23

rack mounting (2-post)

IDS-4235/4250 4-28

IPS-4260 6-12

rack mounting (4-post)

IDS-4235/4260 4-18

IPS-4260 6-9

racks configuration guidelines 1-23

removing

AIP-SSM 7-5

IPS-4260 chassis cover 6-18

NM-CIDS 9-9

SCSI hard-disk drives (IDS-4235/4250) 4-17

replacing IPS-4260 chassis cover 6-18

requirements AIP-SSM 7-2

resetting IDSM-2 8-13

RJ-45 cable pinouts 1-28

RJ-45 to DB2-5 cable pinouts 1-29

RJ-45 to DB-9 cable pinouts 1-29

S

security information Cisco Security Center 11-13

sensing interfaces

described 1-4

modes 1-4

PCI cards 1-4

sensors

AIP-SSM 1-15

capturing traffic 1-1

comprehensive deployment 1-1

Comprehensive Deployment Solutions (illustration) 1-1

electrical guidelines 1-24

IDS mode 1-1

incorrect NTP configuration 1-21

initializing 10-1, 10-2

interface support 1-5

IPS mode 1-1

license 11-9

models 1-11

network topology 1-11

NTP time synchronization 1-19

power supply guidelines 1-25

preparing for installation 1-22

rack configuration guidelines 1-23

recovering the system image 11-6

reimaging 11-6

setup command 10-1, 10-2

site guidelines 1-23

supported 1-11

TCP reset 1-2

time sources 1-19

unsupported 1-12

service packs described 11-4

setting up a terminal server 1-14

setup command 10-1, 10-2

show module 1 command 7-4

signature/virus update files described 11-4

signature engine update files described 11-4

site guidelines 1-23

slot assignments

IDSM-2 8-5

supervisor engines 8-5

software bypass with hardware bypass 6-4

software downloads Cisco.com 11-1

software file names

recovery (illustration) 11-5

signature/virus updates (illustration) 11-4

signature engine updates (illustration) 11-4

system image (illustration) 11-5

SPAN

appliances 1-13

IDSM-2 1-16

specifications

AIP-SSM 7-1

IDS-4215 3-3

IDS-4235/4250 4-6

IDSM-2 8-1

IPS-4240/4255 5-4

IPS-4260 6-8

NM-CIDS 9-1

status AIP-SSM 7-4

Switched Port Analyzer see SPAN

System Configuration Dialog 10-1

T

TCP reset 1-2

TCP reset interfaces

conditions 1-8

described 1-7

list 1-7

TCP reset port IDSM-2 8-3

terminal servers setting up 1-14

testing fail-over 6-4

TFTP servers

recommended 3-9

UNIX 3-9

Windows 3-9

time correcting on the sensor 1-22

time sources

AIP-SSM 1-20

appliances 1-19

IDSM-2 1-19

NM-CIDS 1-20

time synchronization IPS modules 1-21

troubleshooting TCP reset interfaces 4-8

U

understanding time on the sensor 1-19

unsupported sensors 1-12

upgrading

4.1 to 5.0 11-6

minimum required version 11-6

URLs Cisco Security Center 11-13

using TCP reset interfaces 1-8

V

VACLs IDSM-2 1-16

verifying

IDSM-2 installation 8-8

sensor initialization 10-8

sensor setup 10-8

X

XL cards fiber ports 4-16