Contents
v
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Correcting Time on the Sensor
3-36
Configuring Time on the Sensor
3-36
Displaying the System Clock
3-37
Manually Setting the System Clock
3-37
Configuring Recurring Summertime Settings
3-38
Configuring Nonrecurring Summertime Settings
3-40
Configuring Time Zones Settings
3-42
Configuring NTP
3-42
Configuring a Cisco Router to be an NTP Server
3-43
Configuring the Sensor to Use an NTP Time Source
3-44
Configuring SSH
3-45
Understanding SSH
3-46
Adding Hosts to the SSH Known Hosts List
3-46
Adding Authorized RSA1 and RSA2 Keys
3-48
Generating the RSA Server Host Key
3-49
Configuring TLS
3-51
Understanding TLS
3-51
Adding TLS Trusted Hosts
3-52
Displaying and Generating the Server Certificate
3-53
Installing the License Key
3-54
Understanding the License Key
3-54
Service Programs for IPS Products
3-55
Obtaining and Installing the License Key
3-55
Licensing the ASA 5500-X IPS SSP
3-57
Uninstalling the License Key
3-58
CHAPTER
4
Configuring Interfaces
4-1
Interface Notes and Caveats
4-1
Understanding Interfaces
4-2
IPS Interfaces
4-2
Command and Control Interface
4-3
Sensing Interfaces
4-4
TCP Reset Interfaces
4-4
Understanding Alternate TCP Reset Interfaces
4-4
Designating the Alternate TCP Reset Interface
4-5
Interface Support
4-6
Interface Configuration Restrictio ns
4-8
Interface Configuration Sequence
4-10
Configuring Physical Interfaces
4-11