Using IPS Device Manager: © 2005, Cisco Systems, Inc. All Rights Reserved

Download as ppt, pdf, or txt
Download as ppt, pdf, or txt
You are on page 1of 38

Using IPS Device

Manager

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-1

Introduction to the IPS


Device Manager

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-2

IPS Device Manager

IDM is a web-based
application that
enables you to
configure, manage,
and monitor the
sensor.
The IDM web server
resides on the
sensor and can be
accessed via your
web browser.

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-3

IDM Features and Benefits


Web-based embedded architecture
Task-based GUI

Configuration and monitoring


Sensor system administration
Signature grouping

Signature customization
Secure communication (TLS and SSL)

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-4

TLS and SSL Communications

IDM
IDM

HTTPS Client

HTTPS
(TLS and SSL)
HTTPS Server

TLS and SSL use a process called handshaking that involves a


number of coordinated exchanges between a client and a server.
A trusted host certificate is used by the server to verify the
identity of a connecting client.
A server certificate is used by the server to prove its identity to
the client.
2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-5

IDM System Requirements


Supported operating systems for IDM and
their corresponding supported browsers:
Windows 2000, Windows XP
Internet Explorer 6.0 with Java Plug-In 1.5

Netscape 7.1 with Java Plug-In 1.5


Sun SPARC Solaris 2.8 or 2.9
Mozilla 1.7

Red Hat Linux 9.0 or Red Hat Enterprise Linux WS,


version 3 running GNOME or KDE
Mozilla 1.7
2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-6

Getting Started with the


IDM

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-7

Logging In to the IDM

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-8

Trusting the Sensor

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-9

Trusting Cisco

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-10

License Key Warning

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-11

IDM User Interface


Back

Forward

Refresh

Help

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-12

Online IDM Help

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-13

Configuring Network Settings

Configuration
Sensor Setup
Hostname
IP Address
Network
Mask

Network

Default
Route

Reset
Web
Server
Settings
2005 Cisco Systems, Inc. All rights reserved.

Remote
Access

IPS v5.04-14

Configuring Certificates

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-15

Server Certificate
Configuration
Sensor Setup
Certificates

Server
Certificate

Generate
Certificate

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-16

Trusted Hosts
D

Trusted
Hosts

Add

IP Address

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-17

Trusted Hosts (Cont.)

View

Delete

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-18

Configuring SSH

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-19

SSH Communications
The clients key (SSH authorized key) enables the
client to connect without password authentication.
The servers key (SSH host key) is used by the
sensor to prove its identity to the client.

CLI

SSH
SSH
Client

2005 Cisco Systems, Inc. All rights reserved.

SSH
Server

IPS v5.04-20

SSH Authorized Keys


Configuration
Sensor Setup

SSH

2005 Cisco Systems, Inc. All rights reserved.

Authorized
Keys

Add

IPS v5.04-21

SSH Authorized Keys (Cont.)

ID

Modulus Length

Public
Exponent

Public
Modulus

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-22

SSH Authorized Keys (Cont.)

Edit
Delete

Apply

Reset

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-23

Sensor SSH Host Key

Sensor
Key

Generate
Key

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-24

Known Host Keys

Add

Known
Host
Keys

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-25

Known Host Keys (Cont.)

IP Address

Retrieve
Host Key

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-26

Known Host Keys (Cont.)

Modulus Length

Public
Exponent

Public
Modulus

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-27

Known Host Keys (Cont.)

Edit
Delete

Apply

2005 Cisco Systems, Inc. All rights reserved.

Reset

IPS v5.04-28

Rebooting and Shutting


Down the Sensor

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-29

Rebooting the Sensor


Configuration

Reboot
Sensor

Reboot
Sensor

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-30

Shutting Down the Sensor


Configuration

Shut Down
Sensor

2005 Cisco Systems, Inc. All rights reserved.

Shut Down
Sensor

IPS v5.04-31

Viewing Events in IDM

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-32

The Events Panel


The Events panel enables you to do the following:
Filter event data

View event data


You can filter events based on the following:
Type

Time
Both type and time

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-33

Configuring the Event Display


Monitoring

Events

Select
the
number
of rows
per
page

To configure
events by type

To configure
events by time
View

2005 Cisco Systems, Inc. All rights reserved.

Reset

IPS v5.04-34

Viewing the Events


#

Type

Sensor UTC Time

Event ID

Events

Sig ID

Details

Next
Back
2005 Cisco Systems, Inc. All rights reserved.

Close
Help
IPS v5.04-35

Viewing Event Details

2005 Cisco Systems, Inc. All rights reserved.

IPS v5.04-36

Summary

2005, Cisco Systems, Inc. All rights reserved.

IPS v5.04-37

You might also like