IPS50SL12
IPS50SL12
sensor#
show inventory
• Displays PEP information for the sensor hardware
sensor#
show statistics { analysis-engine |
authentication | denied-attackers | event-server
| event-store| host | logger | network-access |
notification | sdee-server | transaction-source
|virtual-sensor [name]| web-server } [ clear ]
sensor#
show interfaces {fastethernet | gigabitethernet
| management } [slot/port]
• Displays statistics for system interfaces
sensor#
packet capture interface-name [snaplen length]
[count count] [expression expression]
• Captures traffic on an interface in real time
sensor1# packet capture FastEthernet0/1
Warning: This command will cause significant
performance degradation
tcpdump: WARNING: fe0_1: no IPv4 address assigned
tcpdump: listening on fe0_1, link-type EN10MB
(Ethernet), capture size 65535 bytes
15 packets captured
15 packets received by filter
0 packets dropped by kernel
• Captures traffic on Fast Ethernet 0/1
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—12-7
Displaying Traffic Captured from an
Interface
sensor#
packet display packet-file [verbose] [expression expression]
• Displays a previously captured file
sensor#
packet display file-info
• Displays information about a previously captured file
sensor#
packet display interface-name [snaplen length] [count count]
[verbose] [expression expression]
• Displays live traffic as it passes the specified interface
sensor#
packet display iplog id [verbose] [expression expression]
• Displays an existing IP log
sensor#
show tech-support[page][password][destination-url
destination-url]
• Displays the current system status
Monitoring
Support
Information
Diagnostics
Report
Generate
Report
Monitoring
Support
Information
Statistics
Refresh
Monitoring
Support
Information
System
Information
Refresh
Configuration
Enable SNMP
Gets/Sets
SNMP
Read-Write
Community String
SNMP General
Configuration
Sensor Location
Apply Reset
• The 4240 and 4255 sensor contain a UDI, which provides the
following benefits:
– Gives you the ability to electronically inventory Cisco products
accurately and reliably
– Simplifies product identification
– Provides consistent product identification across products
• You can retrieve the UDI, a deliverable of the Cisco PEP via
the show inventory command.
• The CLI contains the following useful troubleshooting
commands:
– show statistics: Provides a snapshot of the current internal state of sensor
services
– show interfaces: Provides statistics for sensor interfaces
– packet: Captures or displays live traffic on an interface
– show tech-support: Captures all status and configuration information on
the sensor
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—12-16
Summary (Cont.)
Web
FTP
.50
172.26.26.0
.150
172.30.P.0 .1 .1 172.30.Q.0
.2 .2
RBB
prP prQ
172.16.Q.0
172.16.P.0 .1 .1
.4 .4
sensorP sensorQ
.2 .2
rP rQ
10.0.P.0 .2 .2 10.0.Q.0
.100
.100
RTS
RTS
Student PC Student PC
10.0.P.12 10.0.Q.12
© 2005 Cisco Systems, Inc. All rights reserved. IPS v5.0—12-19