A-15
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix A System Architecture
MainApp
Maintaining blocking state across network device restarts
The ARC reapplies blocks and removes expired blocks as needed whenever a network device is shut
down and restarted. The ARC is not affected by simultaneous or overlapping shutdowns and restarts
of the ARC.
Authentication and authorization
The ARC can establish a communications session wi th a network device that uses AAA
authentication and authorization including the use of remote TACACS+ servers.
Two types of blocking
The ARC supports host blocks and network blocks. Host blocks are connection based or
unconditional. Network blocks are always unconditional.
NAT addressing
The ARC can control network devices that use a NAT address for the sensor. If you specify a NAT
address when you configure a network device, that address is used instead of the local IP address
when the sensor address is filtered from blocks on that device.
Single point of control
The ARC does not share control of network devices with administrators or other software. If you
must update a configuration, shut down ARC until the change is complete. You can enable or disable
the ARC through the CLI or any Cisco IPS manager. When the ARC is reenabled, it completely
reinitializes itself, including rereading the current configuration for each controlled network device.
Note
We recommend that you disable the ARC from blocking when you are configuring any
network device, including firewalls.
Maintains up to 250 active blocks at any given time
The ARC can maintain up to 250 active blocks at a time. Although the ARC can support up to 65535
blocks, we recommend that you allow no more than 250 at a tim e.
Note
The number of blocks is not the same as the number of interface and directions.
Supported Blocking Devices
The ARC can control the following devices:
Cisco routers running Cisco IOS 11.2 or later
Note
To perform rate limiting, the routers must be running Cisco IOS12.3 or later.
Catalyst 5000 series switches with Supervisor Engine software 5.3(1) or later running on the
supervisor engine, and IOS 11.2(9)P or later running on the RSM.
Note
You must have the RSM because blocking is performed on the RSM.
Catalyst 6000 series switches with PFC installed running Catalyst software 5.3 or later