14-21
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter1 4 Configuring Attack Response Controller for Blocking and Rate Limiting
Configuring Blocking and Rate Limiting Devices
Enter password[]: ********
Re-enter password ********
Step 6
Specify the enable password for the user.
sensor(config-net-use)# enable-password
Enter enable-password[]: ********
Re-enter enable-password ********
Step 7
Verify the settings.
sensor(config-net-use)# show settings
profile-name: PROFILE1
-----------------------------------------------
enable-password: <hidden>
password: <hidden>
username: jsmith default:
-----------------------------------------------
sensor(config-net-use)#
Step 8
Exit network access submode.
sensor(config-net-use)# exit
sensor(config-net)# exit
Apply Changes:?[yes]:
Step 9
Press Enter to apply the changes or enter
no
to discard them.
Configuring Blocking and Rate Limiting Devices
This section describes how to configure devices that the sensor uses to perform blocking o r rate limiting.
It contains the following topics:
How the Sensor Manages Devices, page 14-21
Configuring the Sensor to Manage Cisco Routers, page 14-22
Configuring the Sensor to Manage Catalyst 6500 Series Switches and Cisco 7600 Series Routers,
page 14-25
Configuring the Sensor to Manage Cisco Firewalls, page 14-27

How the Sensor Manages Devices

Note
ACLs do not apply to rate limiting devices.
The ARC uses ACLs on Cisco routers and switches to manage those devices. These ACLs are built as
follows:
1.
A permit line with the sensor IP address or, if specified, the NAT address of the sensor.
Note
If you permit the sensor to be blocked, this line does not a ppear in the ACL.
2.
Pre-Block ACL (if specified). This ACL must already exist on the device.