Cisco IPS-4255-K9 Installation Guide - Page 348

Gathering Information, Health and Network Security Information

Page 348 highlights

Gathering Information Chapter A Troubleshooting You cannot bring up, enable, or configure a disabled module. To bring up a less capable module, you must remove the more capable module from the router and reboot. Disabled modules are reported in the show diag command output. The state of the module is reported as present but disabled. If the most capable module slot and port do not match the interface ids slot/port configuration command, the most capable module is disabled with the following warning: The module in slot x will be disabled and configuration ignored. The correct slot/port number are displayed so that you can change the configuration. For More Information For more information on the NM CIDS, refer to Introducing the NM CIDS and Installing the NM CIDS. Gathering Information You can use the following CLI commands and scripts to gather information and diagnose the state of the sensor when problems occur. You can use the show tech-support command to gather all the information of the sensor, or you can use the other individual commands listed in this section for specific information. This section describes how to use CLI commands to obtain information about your sensor, contains the following topics: • Health and Network Security Information, page A-70 • Tech Support Information, page A-71 • Version Information, page A-74 • Statistics Information, page A-76 • Interfaces Information, page A-87 • Events Information, page A-88 • cidDump Script, page A-92 • Uploading and Accessing Files on the Cisco FTP Site, page A-93 Health and Network Security Information Use the show health command in privileged EXEC mode to display the overall health status information of the sensor. The health status categories are rated by red and green with red being critical. Caution When the sensor is first starting, it is normal for certain health metric statuses to be red until the sensor is fully up and running. To display the overall health status of the sensor, follow these steps: Step 1 Step 2 Log in to the CLI. Show the health and security status of the sensor. sensor# show health Overall Health Status Health Status for Failed Applications Health Status for Signature Updates Red Green Green A-70 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 OL-18504-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412

A-70
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
OL-18504-01
Chapter A
Troubleshooting
Gathering Information
You cannot bring up, enable, or configure a disabled module. To bring up a less capable module, you
must remove the more capable module from the router and reboot. Disabled modules are reported in the
show diag
command output. The state of the module is reported as present but disabled.
If the most capable module slot and port do not match the
interface ids slot/port
configuration
command, the most capable module is disabled with the following warning:
The module in slot x will be disabled and configuration ignored.
The correct slot/port number are displayed so that you can change the configuration.
For More Information
For more information on the NM CIDS, refer to
Introducing the NM CIDS
and
Installing the NM CIDS
.
Gathering Information
You can use the following CLI commands and scripts to gather information and diagnose the state of the
sensor when problems occur. You can use the
show tech-support
command to gather all the information
of the sensor, or you can use the other individual commands listed in this section for specific
information. This section describes how to use CLI commands to obtain information about your sensor,
contains the following topics:
Health and Network Security Information, page A-70
Tech Support Information, page A-71
Version Information, page A-74
Statistics Information, page A-76
Interfaces Information, page A-87
Events Information, page A-88
cidDump Script, page A-92
Uploading and Accessing Files on the Cisco FTP Site, page A-93
Health and Network Security Information
Use the
show health
command in privileged EXEC mode to display the overall health status information
of the sensor. The health status categories are rated by red and green with red being critical.
Caution
When the sensor is first starting, it is normal for certain health metric statuses to be red until the sensor
is fully up and running.
To display the overall health status of the sensor, follow these steps:
Step 1
Log in to the CLI.
Step 2
Show the health and security status of the sensor.
sensor#
show health
Overall Health Status
Red
Health Status for Failed Applications
Green
Health Status for Signature Updates
Green