Section 6.0: Intrusion Detection System (IDS) (6 points)

6.1. Intrusion Detection System (IDS) (3 points)

  1. Configure Cisco IDS sensor as shown in Figure 5-1.

  2. Configure the Command and Control interface with IP address 172.16.1.3 in VLAN-2.

  3. Configure the Sensing interface to monitor VLAN-3 and VLAN 4.

  4. Use IDM (IDS Device Manager) to configure sensor parameters and IEV (IDS Event Viewer) to receive alarms from the sensor.

6.2. Advanced Intrusion Detection System (IDS) (3 points)

  1. Change the ICMP echo signature to HIGH severity. Ping any device in VLAN 3 or 4 and make sure you receive alarms in IEV.

  2. Configure a custom signature 55055 to trigger HIGH severity when any Telnet session tries to change the password on any device monitored.

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.