3-2
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter 3 Setting Up the Sensor
Understanding Sensor Setup
You cannot use the privilege command to give a user service privileges. If you want to give an
existing user service privileges, you must remove that user and then use the username command to
create the service account.
Do not make modifications to the sensor through the service account except u nder the direction of
TAC. If you use the service account to configure the sensor, your configuration is not supported by
TAC. Adding services to the operating system through the service account affects proper
performance and functioning of the other IPS services. TAC does not support a sensor on which
additional services have been added.
You should carefully consider whether you want to create a service account. The service account
provides shell access to the system, which makes the system vulnerable. However, you can use the
service account to create a password if the administrator password is lost. Analyze your situa tion to
decide if you want a service account existing on the system.
Administrators may need to disable the password recovery feature for security reasons.
We recommend that you use an NTP server to regulate time on your sensor. You can use
authenticated or unauthenticated NTP. For authenticated NTP, you must obtain the NTP server IP
address, NTP server key ID, and the key value from the NTP server. You can set up NTP during
initialization or you can configure NTP through the CLI, IDM, IME, or ASDM.
In addition to a valid Cisco.com username and password, you must also have a Cisco Services for
IPS service contract before you can apply for a license key.
Understanding Sensor Setup
Setting up the sensor involves such tasks as changing sensor initialization information, adding and
deleting users, configuring time and setting up NTP, creating a service account, configuring SSH and
TLS, and installing the license key. You configured most of these settings when you initialized the sensor
using the setup command.
For More Information
For more information on using the setup command to initialize the sensor, see Chapter 2, “Initializing
the Sensor.”
Changing Network Settings
After you initialize your sensor, you may need to change some of the network settings that you
configured when you ran the setup command. This section describes how to change network settings,
and contains the following topics:
Changing the Hostname, page 3-3
Changing the IP Address, Netmask, and Gateway, page 3-4
Enabling and Disabling Telnet, page 3-5
Changing the Access List, page3-6
Changing the FTP Timeout, page 3-8
Adding a Login Banner, page 3-9
Configuring the DNS and Proxy Servers for Global Correlation and Au tomatic Update, page 3-10
Enabling SSHv1 Fallback, page 3-13