CHAPT ER
3-1
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
3
Setting Up the Sensor
This chapter contains procedures for the setting up the sensor, and contains the following sections:
Setup Notes and Caveats, page 3-1
Understanding Sensor Setup, page 3-2
Changing Network Settings, page 3-2
Changing the CLI Session Timeout, page 3-14
Changing Web Server Settings, page 3-15
Configuring Authentication and User Parameters, page 3-18
Configuring Time, page 3-35
Configuring SSH, page 3-45
Configuring TLS, page3-51
Installing the License Key, page 3-54

Setup Notes and Caveats

The following notes and caveats apply to setting up the sensor:
By default SSHv2 is enabled and SSHv1 is disabled.
When updating the hostname, the CLI prompt of the current session and other existing sessions is
not updated with the new hostname immediately. Subsequent CLI login sessions reflect the new
hostname in the prompt.
Telnet is not a secure access service and therefore is disabled by default on the sensor. However,
SSH is always running on the sensor and it is a secure service.
For automatic and global correlation updates to function, you must h ave either a DNS server or an
HTTP proxy server configured at all times.
DNS resolution is supported for accessing the global correlation update server as well as
www.cisco.com for automatic updates.
The default web server port is 443 if TLS is enabled and 80 if TLS is disabled.
The username command provides username and password authentication for login purposes only.
You cannot use this command to remove a user who is logged in to the system. You cannot use this
command to remove yourself from the system.