Cisco IPS-4255-K9 Installation Guide - Page 344
Using the TCP Reset Interface, Connecting a Serial Cable to the IDSM2, Troubleshooting the AIP SSM
UPC - 746320951096
View all Cisco IPS-4255-K9 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 344 highlights
Troubleshooting the AIP SSM Chapter A Troubleshooting Using the TCP Reset Interface The IDSM2 has a TCP reset interface-port 1. The IDSM2 has a specific TCP reset interface because it cannot send TCP resets on its sensing ports. If you have reset problems with the IDSM2, and the switch is running Catalyst software, try the following: • If the sensing ports are access ports (a single VLAN), you need to configure the reset port to be in the same VLAN. • If the sensing ports are dot1q trunk ports (multi-VLAN), the sensing ports and reset port all must have the same native VLAN, and the reset port must trunk all the VLANs being trunked by both the sensing ports. Note In Cisco IOS when the IDSM2 is in promiscuous mode, the IDSM2 ports are always dot1q trunk ports (even when monitoring only 1 VLAN), and the TCP reset port is automatically set to a trunk port and is not configurable. For More Information For more information about the IDSM2 and TCP reset, refer to Configuring the IDSM2. Connecting a Serial Cable to the IDSM2 You can connect a serial cable directly to the serial console port on the IDSM2. This lets you bypass the switch and module network interfaces. To connect a serial cable to the IDSM2, follow these steps: Step 1 Step 2 Step 3 Locate the two RJ-45 ports on the IDSM2. You can find them approximately in the center of the mother board. If you are facing the module faceplate, the RJ-45 port on the right is the serial console port. Connect a straight-through cable to the right port on the IDSM2, and then connect the other end of the cable to a terminal server port. Configure the terminal server port to be 19200 baud, 8 bits, no parity. You can now log directly in to the IDSM2. Note Connecting a serial cable to the IDSM2 works only if there is no module located above the IDSM2 in the switch chassis, because the cable has to come out through the front of the chassis. Troubleshooting the AIP SSM The following section contains information for troubleshooting the AIP SSM, and contains the following topics: • Health and Status Information, page A-67 • The AIP SSM and the Data Plane, page A-69 • A-66 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 OL-18504-01