A-1
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
APPENDIX
A

System Architecture

This appendix describes the IPS system architecture, and contains the following sections:
IPS System Design, page A-1
System Applications, page A-3
•Recovery partition—A special purpose image used for recovery of the sensor. Booting into the
recovery partition enables you to completely reimage the application partition. Network settings are
preserved, but all other configuration is lost.User Interaction, page A-4
Security Features, page A-5
MainApp, page A-6
SensorApp, page A-22
CollaborationApp, page A-27
SwitchApp, page A-29
CLI, page A-30
Communications, pageA-31
Cisco IPS File Structure, page A-34
Summary of Cisco IPS Applications, page A-35

Understanding the IPS System Architecture

The purpose of the Cisco IPS is to detect and prevent malicious network activity. You can install the
Cisco IPS software on two platforms: appliances and the modules. The Cisco IPS contains a manage ment
application and a monitoring application. The IDM is a network management JAVA application that you
can use to manage and monitor the IPS. The IME is an IPS network monitoring JAVA application that
you can use to view IPS events. The IME also contains the IDM configuration component. The IDM and
the IME communicate with the IPS using HTTP or HTTPS and are hosted on your computer.

IPS System Design

The Cisco IPS software runs on the Linux operating system. We have hardened the Linux OS by
removing unnecessary packages from the OS, disabling unused services, restricting network access, and
removing access to the shell.