11-7
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 1 Configuring External Product Interfaces
Adding External Product Interfac es and Posture ACLs
Step 9
(Optional) Allow the host posture information from unreachable hosts to be passed from the external
product to the sensor.
sensor(config-ext-cis-hos)# allow-unreachable-postures yes
Note
A host is not reachable if the CSA MC cannot establish a connection with the host on any of the
IP addresses in the host’s posture. This option is useful in filtering the postures whose IP
addresses may not be visible to the IPS or may be duplicated across the network. This filter is
most applicable in network topologies where hosts that are not reachable by the CSAMC are
also not reachable by the IPS, for example if the IPS and the CSAMC are on the same network
segment.
Step 10
Configure a posture ACL:
a.
Add the posture ACL into the ACL list.
sensor(config-ext-cis-hos)# posture-acls insert name1 begin
sensor(config-ext-cis-hos-pos)#
Note
Posture ACLs are network address ranges for which host postures are allowed or denied. U se
posture ACLs to filter postures that have IP addresses that may not be visible to the IPS or
may be duplicated across the network.
b.
Enter the network address the posture ACL will use.
sensor(config-ext-cis-hos-pos)# network-address 192.0.2.0/24
c.
Choose the action (deny or permit) the posture ACL will take.
sensor(config-ext-cis-hos-pos)# action permit
Step 11
Verify the settings.
sensor(config-ext-cis-hos-pos)# exit
sensor(config-ext-cis-hos)# exit
sensor(config-ext-cis)# exit
sensor(config-ext)# show settings
cisco-security-agents-mc-settings (min: 0, max: 2, current: 1)
-----------------------------------------------
ip-address: 209.165.200.225
-----------------------------------------------
interface-type: extended-sdee <protected>
enabled: yes default: yes
url: /csamc50/sdee-server <protected>
port: 80 default: 443
use-ssl
-----------------------------------------------
always-yes: yes <protected>
-----------------------------------------------
username: jsmith
password: <hidden>
host-posture-settings
-----------------------------------------------
enabled: yes default: yes
allow-unreachable-postures: yes default: yes
posture-acls (ordered min: 0, max: 10, current: 1 - 1 active, 0 inactive)
-----------------------------------------------
ACTIVE list-contents