C-35
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Appendix C Troubleshooting
Troubleshooting the Appliance
Step 8
Start the IPS services.
sensor# cids start
Step 9
Log in to an account with administrator privileges.
Step 10
Reboot the sensor.
sensor# reset
Warning: Executing this command will stop all applications and reboot the node.
Continue with reset? [yes]:yes
Request Succeeded.
sensor#
For More Information
To learn more about IPS system architecture, see Appendix A, “System Architecture.”
Blocking
This section provides troubleshooting help for blocking and the ARC service. It contains the following
topics.
Troubleshooting Blocking, page C-35
Verifying the ARC is Running, pageC-36
Verifying ARC Connections are Active, pageC-37
Device Access Issues, page C-39
Verifying the Interfaces and Directions on the Network Device, pageC-40
Enabling SSH Connections to the Network Device, page C-41
Blocking Not Occurring for a Signature, page C-41
Verifying the Master Blocking Sensor Configuration, page C-42

Troubleshooting Blocking

After you have configured the ARC, you can verify if it is running properly by using the show version
command. To verify that the ARC is connecting to the network devices, use the show statistics
network-access command.
Note
The ARC was formerly known as Network Access Controller. Although the name has been changed
since IPS 5.1, it still appears in IDM, IME, and the CLI as Network Access Controller, nac, and
network-access.
To troubleshoot the ARC, follow these steps:
1.
Verify that the ARC is running.
2.
Verify that the ARC is connecting to the network devices.
3.
Verify that the Event Action is set to Block Host for specific signatures.
4.
Verify that the master blocking sensor is properly configured.