JOINT-2-data ports

Hello

I took over managing a JOINT-2 6500 implementation, as far as I can see it has been configured in

"Promiscuous" mode with a single virtual sensor assigned to two data ports 0/7 & 0/8.

The switch was configured with the following options:

intrusion detection module 8 access management port - vlan 507
intrusion detection module 8 ports data access 1 - vlan 507

monitor the 66 session source vlan 501-509, 518-520, 601-613
monitor the session 66 intrusion-detection-module 8-port data destination 2

can someone tell me why the data port of second order utilsed 1 and the background command uses the data port 2, it's valid and recommended?

Thank you

D

So a little bit about the architecture of the JOINT.

JOINT has a management or command and control (gig0/2) port and 2 data (gig0/7 & gig0/8) ports

These ports on JOINT connect to the 6500 on the backplane.

JOINT Gig0/7 connects to the data port 1 on 6500.

JOINT Gig0/8 connects to the data port 2 on 6500.

The configuration involves two things:

1 setting up JOINT (Date, time, assigning virtual devices to interfaces, tuning signature... etc.)

2. configuration of 6500 to send traffic to the JOINT.

You plan to put the JOINT in promiscuity or inline mode?

The configuration on the 6500 is different for the two modes.

Configuration:

intrusion detection module 8 access management port - vlan 507

This puts the management port to vlan 507

intrusion detection module 8 ports data access 1 - vlan 507

Puts data port 1 in vlan 507. This is usually done in inline mode.

monitor the 66 session source vlan 501-509, 518-520, 601-613
monitor the session 66 intrusion-detection-module 8-port data destination 2

It is an extended configuration that sends a copy of the data from the VLANs to the port of data 2.

This is done when JOINT running in promiscuous mode.

So in your case, the configuration is correct on 6500 sending traffic to JOINT depends on what mode, you want the METHOD to be run in.

Please see the link below which will explain how to configure 6500 promiscuity or JOINT configuration in inline mode.

http://www.Cisco.com/en/us/docs/security/IPS/7.0/Configuration/Guide/CLI/cli_idsm2.html

Let me know if you have any questions.

-Sid

Tags: Cisco Security

Similar Questions

  • hidden data port 2 on Mac Pro 1.1

    No one knows what that Apple engineers have reason had to have these two ports on the motherboard? Discussions I read suggested that they were for the installation of additional optical drives, but I just watched a youtube video that has already shown the optical drive port has additional sata cables already in there.

    2 are there thing, data ports, but I don't see a pair of extra power cables. It has been designed a bit more from the Commission? Or was there a plan that Apple abandoned.

    Wiring in optical bays in Mac Pro 1.1 to 3.1 2008 model have ATA/IDE wiring in optical bays, connectors from molex power 4pin.

    In my view, Apple has included these two additional SATA ports to guard against optical disk ATA/IDE, becoming too expensive or outdated form. Additional ports gave them the data connection to allow them to switch to SATA optical drives (with duplicator of molex power 4pin or adapter) without revision of the motherboard.

    There is no explanation of how to use them in any official literature from Apple. They are too close, and using both requires using at least a right angle connector. Practical power is expected, because they were never for your convenience. Research of power for additional disks attached here is your problem. (learn about amateur sites)

    For the great re-design for the 2009 model, these ports were eliminated, and the optical bays got SATA wiring (including power SATA).

  • ENVY 700-527c: data port availability

    ENVY 700-527c, regarding with card mother Kaili2.

    This unit had a place available for an additional cd/dvd drive for a total of 2 cd/dvd players.

    In addition, there are two bays available for the additional hard drives for a total of 3hdds.

    I installed a dvd drive in the extra Bay and I installed a hard drive in one of the two available bays. Everything works well no problems.

    I would like to take advantage of the third Bay for an additional hard drive, but there were only two available data ports.

    You can see the data ports in the lower right. Currently, all four are busy (2 dvd/cd drives - hard drive 2).

    My question is: How can I get a third HDD installed and operational?

    Hello

    The RED edge connector is a different SATA port.  See the image below.

    Motherboard taken Kaili2 supported by six SATA 6 devices. Five traditional SATA III ports and an MSATA are available.

  • What is a data port?

    Hello

    I'm confused at first data ports. The ports of database the same as the listener ports?

    I have 15 databases on our windows 2003 server. Combination of 9i, 10g, 11g

    It has 3 types of headphones for 9i, 10g and 11g.

    5 Database 9i uses listener9i with port 1521 = > does that mean their database port is 1521?
    5 10 g database using listener10g with port 1522 = > does that mean their database port is 1522?
    5 11 g database using listener11g with port 1523 = > does that mean their database port is 1523?

    If I merge all 3 headphones in the earphone of 11g with port 1523. Does this mean all my 15 databases has the same port which is 1523?

    Is it possible that 1 database can be registered 3 listeners, so it can have 3 different ports?

    It follows, then, that the port of the database is not send to each database?



    Thank you

    Published by: 843228 on April 11, 2011 03:19

    843228 wrote:
    Hello

    I'm confused at first data ports. The ports of database the same as the listener ports?

    I have 15 databases on our windows 2003 server. Combination of 9i, 10g, 11g

    It has 3 types of headphones for 9i, 10g and 11g.

    5 Database 9i uses listener9i with port 1521 ===> is does that mean their database port is 1521?
    5 10 g database using listener10g with port 1522 ===> is does that mean their database port is 1522?
    5 11 g database using listener11g with port 1523 ===> is does that mean their database port is 1523?

    If I merge all 3 headphones in the earphone of 11g with port 1523. Does this mean all my 15 databases has the same port which is 1523?

    Is it possible that 1 database can be registered 3 listeners, so it can have 3 different ports?

    It follows, then, that the port of the database is not send to each database?

    Thank you

    Published by: 843228 on April 11, 2011 03:19

    the fundamental flaw in your thinking is that databases do not use ports at all! The listener uses a port to listen for connection requests. A listener, with the default LISTENER name, running an oracle home, listening on a single port, use easily - is designed to serve--multiple instances of database in several versions of several houses. It is unnecessary complexity to try to have several headphones or to name the listener as if she belongs to a customer or a specific database. It's like the telephone company, to build a separate table for each customer.

  • N2048 - VoIP QoS, data Ports and trunk Configurations

    Hi all

    I am new here and also new to work with the Dell Networking hardware. I just need to some insights into setting up a new network, that I put. We use 3 switches to N2048 for access to data and VoIP. Each port will have only have only a phone or a client PC in different VLANS.

    My question is what is the best configuration across all three powered to ensure that we have the optimum configuration for the quality of service for VoIP phones. Here is the configuration that I came up with this day.

    Global configuration

    VLAN, VoIP

    Voice port

    item in gi1/0/1 interface
    switchport mode access
    switchport access vlan 5
    VLAN 5 voices
    Voice vlan dot1p 5
    output

    Client port PC

    access mode swithport
    swithport access vlan 10

    Trunk Port

    Te1/0/1 interface
    switchport mode general
    VLAN allowed switchport General add 5,10,100
    switchport General pvid 100
    VLAN 5 voices
    output

    Thanks for the comments

    By default, the ports are configured to trust the priority of incoming user. So for your switch connections you can configure ports and trunk mode, there is no need to set general mode with VLANs voice, etc.

    switchport mode trunk

    switchport trunk allowed vlan add 5, 10, 100

    switchport trunk vlan 100 native

    For ease of deployment, I suggest to all the other general mode ports.

    switchport mode general

    VLAN allowed switchport General add 5,10

    pvid switchport General 10

    VLAN 5 voices

    With the general mode configuration, you can connect a client or a phone, or both at the same time, in a port. This will make things easy if later you decide to plug a phone in where a customer to reside.

  • TMS DEVICE DATA PORT

    Trying to find in a manual of what should be given on my PC port setting.  Tried N-8-1 @ 9600, 19200, 34800 with no luck?

    Any idea is appreciated... Thank you.

    The device used TMS screen LCD - no data for the configuration port.  The serial port does nothing for the TMS images.

  • 6509 uplink to ASA with pair of Vlan

    I have the following topology:

    6509---> ASA---> Internet.

    My 6509 have a JOINT.

    intrusion detection module 3 management access port - vlan 2

    3-port data module 1 intrusion detection allowed - vlan trunk 352,603,1352,1603

    I want to put the JOINT between 6509 and ASA.

    6509 have a vlan 603 where inside the ASA is connected and I have already created VLANs to briding with 603 1603, this way

    I put the cable inside the ASA to vlan 1603, before was connected on vlan 603 but when I changed switchport vlan

    SAA (603 to vlan 1603) my vlan 603 breaks down and I can't access the internet.

    VLAN 603 down because there is that no user not connected them but I thought that briding how JOINT 603 with 1603

    This vlan 603 will be again, but does not work.

    How can I configure the IDM to this Vlan?

    I guess the switch itself has a 603 interface vlan, and it is this 603 interface vlan that goes down.

    By default the JOINT-2 data ports are configured to exclude "autostate" which means that is the JOINT-2 port and the interface vlan switches are the only things on the vlan, then the switch will lower its interface. The switch does not include the JOINT-2 interface when you are looking for other ports in the vlan.

    There is a command:

    3-port data module 1 intrusion detection autostate include

    With this command the JOINT-2 port will now appear in the list of ports to monitor, and the switch must now implement its 603 interface vlan.

    You can see the list of available commands for the JOINT-2 here:

    http://www.Cisco.com/en/us/docs/security/IPS/7.0/Configuration/Guide/CLI/cli_idsm2.html#wp1032690

  • Pavilion 550-254-112na: Broken data on hard drive WD blue port

    The data port broke on the hard drive. Y at - it a British supplier for a new pcb 2060-771945-002? I can only find overseas with extended delivery. As I have only owned this computer for 2 weeks, I want to make it work again. I know I can get traded locally of the bios chip if necessary. Much dg_hlc thanks

    Hi @dg_hlc!

    Personally, I would say to get a new drive if possible because the problems related to the card of the unit are not easy to solve.

    Of course, you can try to replace it if you want, but I do not recommend. I'm not saying it, not only because it is an operation not caring and not recommended in general, but especially because the risk to damage further the drive is too big and that the chances of finding an exact match of a PCB are really weak because of differences in the firmware over the years.

    The danger is that it can () will have different settings for how align the heads to the tracks on the surface of the physical disk, and when it tries to write anything (which it will) it will result in all current data is erased.

    I hope this helps and good luck!

  • Database - listener Ports - data transfer

    Hello

    If there are two databases running on the server, is it opt to configure the listening port only for two databases? and what happens if a single listening port configured?

    Thank you
    KSG

    Published by: KSG October 16, 2011 23:53
    Hi Jgarry/Hemant

    For client-server data.

    I understand as

    First, the client sends the request to the db server, the Listener listens to the connection and creates a database server process to handle the request (can be a query...

    I just want to understand how the processed information passes to the client... I wanted to say... What are the ports to transfer data from db to the client server?

    Jgarry, I understand the flow of data occurs via a separate data port (for example it can be any port 1599 or something)... So not that any additional traffic occurs between the client-server or client-server use the same data port?

    Im trying to understand the architectural flow of connectivity between the customer and vice versa. that will help better understand.

    My concern is...

    We implement a customer through TNS names connectivity. The listenes connectivity server and creates a server session to run the connectivity. Just as a request from the client to the database listen service_name "orcl", host = protocol = TCP port = 1521 abc.com. that is listening on the side Server and server recoganize the connectivity...

    Here, I am trying to understand... once the connection is established, so it's not need a listening more. We can not even stop the listener. How the portocol TCP in the Oracle Net will establish the flow of data between servers (how goes the sequence of request and response).
    If the network TCP layer is used to interact between the servers then how data flows between servers; as it uses a port number separated to send/receive data.

    Thank you
    KSG


    Thanks in advance
    KSG

    Published by: KSG October 16, 2011 23:55
    (added the more information about the data flow between the client-server)

    See the "Architecture of the listener" section here:
    http://download.Oracle.com/docs/CD/B19306_01/network.102/b14212/architecture.htm#sthref429

    1. a customer identifies the listener of the tnsnames.ora entry and/or command-line (HOST/IP, Port) settings.
    2. He sends the requested SERVICE_NAME / SID to the listener when it is able to connect to the listener.
    3. the Auditor verifies that he is aware of the SERVICE_NAME / SID (if not, it returns an error "listener isn't aware of service"). 'Consciousness' is inspired by PMON the recording with the listener database and/or the SID is used in the listener.ora file.
    4. once the auditor confirms that such a SERVICE_NAME / SID is available...
    5. He requests the service of database at the table a new process (which you will see as a process of oracleSID on a Linux/Unix server or a Thread in the process oracle.exe in Windows).
    6. it transmits customer information (IP address of the client, Protocol, etc.) in the process.
    7. Subsequently, it is this server process which is the authentication of the user (name of username-password), creates a session and manages all client requests (instructions SQL etc.) and returns the results to the client.
    -The listener is no longer involved.

    Hemant K Collette

  • port management and control for nm-cids

    Any body can help me to find the difference between the ip address we use to ID-sensore 1/0 interface and ip address of the sensor and its default gateway

    10.10.10.2/24,10.10.10.1

    JOINT-2 information.

    There are 8 interfaces of interest when it comes to the JOINT-2.

    4 If the interfaces belong to the JOINT-2 itself.

    4 other interfaces are the switch ports connected to these 4 JOINT-2 interfaces.

    The management of the JOINT-2 interface is ' GigabitEthernet0/2 '.

    When you assign an IP to the JOINT-2 is the interface where the IP address is assigned.

    On the backplane of the switch it will connect to a corresponding switch port.

    In the BONE of cat is "/ 2", and in the IOS is the "management-port intrusion detection module.

    These switch ports must be assigned to what ever vlan door network address assigned to the interface JOINT-2 s Gig0/2.

    The ' GigabitEthernet0/7 and GigabitEthernet0/8' JOINT-2 are the JOINT-2 control interfaces and must be assigned to the AnalysisEngine for surveillance.

    On the backplane of the switch they will connect to 2 corresponding switch ports.

    In the BONE of cat, they are "/ 7" and "/ 8", in IOS, they are "detection module of intrusion-modem 1" and "data-port 2". ""

    You will need to set these ports as capture ports if follow on promiscuity, OR vlan unique ports (access-ports) if making pair interface online monitoring or ports of junction If inline vlan pair followed to do.

    "GigabitEthernet0/1" of the JOINT-2 is not configurable on JOINT-2 and is used only for sending TCP resets in promiscuous mode.

    On the backplane of the switch it will connect to a corresponding switch port.

    In the BONE of cat is "/ 1 ' and should be left a trunk port routing all the VLANS. In IOS this port is not considered in the configuration that the user never needs to change the configuration of this port.

    There are also 3 to 6 ports that are visible in the BONE of cat. But none of these 4 ports are connected to anything on the JOINT-2 module itself and can be ignored safely. These ports are not at all in IOS.

  • Flow of JOINT-2

    Cisco Doc said that JOINT-2 rate is 600Mbps in promiscuous mode, so what bitrate I would get if I just send traffic to the data port.

    The actual Note: we have several devices, Cisco IDS, 4215 s up through 4250XLs and JOINT-2s. None of them meeting their nominal number, fall packages most start at 1/3 of their claimed capacity. This is even after several cases of TAC and the extensive investigation by the engineers of TAC and internal developers. Maybe if you stop 90% of the signatures you can get there. Don't believe the hype.

  • JOINT EtherChannel Question

    In the configuration for the METHOD guide, it states:

    To ensure that the same traffic to the two data ports on each JOINT-2, you must set the

    same EtherChannel index to two data ports on each of the JOINT-2, even if they are in the different

    EtherChannel groups.

    Can someone tell me how to change the index EtherChannel? I have successfully data assigned to a port channel ports, but I can't figure out how to change the EtherChannel index.

    I would recommend to re - initialize the two JOINT in SW2 from scratch and try again. OR as a test, you can let go of etherchannel and configure one of them to test things. I recommend also to keep the parameters of tree cover by default and does not change the cost, etc..

    Concerning

    Farrukh

  • Cisco JOINT and IPS hardware bypass

    Hi all

    I have a question about the Cisco JOINT, ASA - AIP - SSM (IPS) and material of the IPS 4200 bypass unit series. Please let me know if the material fails in both cases how to cross traffic. Is there any circumvention of integrated equipment built in the same

    Concerning

    Ankur

    Sorry for the late reply. I've been on vacation for a week.

    ByPass hardware is not available for the JOINT-2 no matter if you use inline vlan pairs or couples inline interface.

    For devices need special interface cards or a hardware bypass switch separate, and none of them are available on the JOINT-2.

    You must configure your network so that there is a second way around the JOINT 2 JOINT-2 failure.

    This can be done with a standard network cable.

    Suppose you have your JOINT-2 configured for inline vlan VLAN 10 matching and 20.

    Configure a standard switchport as an access port on vlan 10.

    Set up an another standard switchport as an access port on vlan 20.

    Now using a standard network cable connect these 2 all switch ports.

    Stop your JOINT-2 and traffic should now be passed through this network cable and your network connectivity must be maintained.

    Bring your JOINT-2 backup, and now spanning tree runs and will choose the JOINT-2 or the network as the main way and the other cable will set in a State of block.

    Run ' show vlan spanning-tree 10 ' and ' show vlan spanning tree 20 "to determine if the cable ports or port JOINT-2 is in a BLK State.»

    If the cable ports are in a State BLK, then you don't need to modify the spanning tree.

    If the JOINT-2 port is in a State BLK, then you need to change the spanning tree cost and/or priority for JOINT-2 port by using the following commands:

    -[No] port-channel channel_number-STP intrusion detection doesn't cost port_cost

    Defines the cost of port tree covering for the data port on the specified module. Without the option restore shipping tree covering for the data port on the module specified in the default value.

    -[not] port-channel channel_number spanning tree priority priority intrusion detection

    Sets the priority of the port spanning tree for the data port on the specified module. Without the option restores the priority of port spanning tree for the data port on the module specified in the default value.

    To learn more about spanning-tree and how these parameters interact with spanning tree you can look through this section of the user guide for the switch or to search cisco.com for documentation of spanning tree:

    http://www.Cisco.com/en/us/partner/docs/switches/LAN/catalyst6500/IOS/12.2Sx/configuration/guide/spantree.html

    NOTE: Your switch must be configured for rapid PVST for failover more rapid. Work with your administrator to switch to determine which spanning tree Protocol is used on your switch. The JOINT-2 does not work with STDS to ensure that STD is not used.

  • JOINT-2 basic configuration

    Hello

    I have some experience with sensors but this is my first time setting up a C6500 with JOINT-2, and I have a few questions of design. The first question is this: can I mix the VACL and large-scale use to capture traffic in the same configuration?

    Customer actually uses VACL to capture traffic of some machines, but he wants now to monitor all traffic from and external partner via a VPN concentrator, so I guess in this case I should use SPAN to monitor VPN port: I'm wrong?

    The config that the customer is more or less the following:

    detection of intrusion data 1-port module 1 module 1-port data 1 intrusion detection capture captures allowed - vlan 1 intrusion detection module 1 data port 2 capture allowed - vlan 1

    Plan ID to access VLAN 10

    corresponds to the ip address in

    direct capture of action

    Plan ID to access VLAN 20

    corresponds to the ip address to

    action forward

    VLAN ID vlan-list filter 1

    extended IP access list

    IP enable any host 192.168.1.1

    allow a host ip 192.168.1.1

    ...

    extended IP access list

    allow an ip

    If I want to use SCOPE, which is the limitation of the number of source ports I can put in the order to "monitor the session?"

    Should I send this "span" traffic detection interface 8 (data-port 2) or I can always send to the data port 1 (detection interface 7)?

    Why there are two sensing interfaces?

    Thanks in advance...

    Ruben

    First thing to understand is that the customer should not configure data 1 and data-port port 2 to see the same traffic.

    The sensor will get duplicate packets and minimize the overall performance of the detector (spending cpu just to throw duplicates) and at worst could cause false positive and negative or even false.

    So the first thing to do is to remove the capture set up configuration data-port 2, so only 1 data port is the packet capture.

    Now that the data port 2 is released until you can configure data ports 2 for something else.

    So if you want to use the span then Yes you can now configure data-port 2 as a destination span port

    Can mix you VACL and Span configurations?

    Yes, but not on the same data port. A data port can be a vacl capture port and the second data port a destination span port.

    However, you want to try to avoid as much as possible of the duplicate packets. So you will want to try and set it up so that traffic will be normally visible on the destination span port will not also view the vacl capture port (means generally change the VACL to not only capture the traffic).

    If you use Span to monitor VPN port?

    Duration is usually the best way to ensure you get all the packages in and out of a specific port. You will need to make sure that you use a port range (instead of a span of vlan) and make sure cover you the tx and rx traffic so that you get both in and out of traffic.

    Also make sure that the traffic that you are covering the traffic not encrypted and non encrypted traffic (which would be ignored by the sensor).

    What is the limitation on the number of source ports?

    I don't know, and I think he can differ depending on your version of IOS and the type of controller. So you must read the configuration for your cat guide 6K determine the limits of your specific switch.

    Should send you traffic to "merged" to 2 ports data or data port 1?

    A data port may not be as well a VACL Capture pore and a destination Span port. So if data-port 1 is configured for the VACL Capture then it cannot be a Span destination port. Configure a port as a VACL Capture port and the port other than the destination Span port.

    Why are there 2 remote sensing interfaces?

    To do similar things to what you ask. So, you can use 2 different surveillance techniques that would not be on a single port. Or to be able to make promiscuity on a port monitoring, while inline vlan pair monitoring IDE oucederomsurlesecondport. Or use 2 ports set inline interface pair followed.

  • JOINT configuration in promiscuous mode?

    Hello

    I have two switch catalyst 6500 in VSS each with a JOINT module, I want to monitor four VLANS three of them is VLAN users and one of the servers, I'm planning use VACL to capture traffic.

    My first question is how to configure the data ports of JOINT in promiscuous mode, if in the configuration guide say that by default data ports are "Promiscuous" mode, which means that I can't do any configuration in the ports of JOINT data?

    Second, if I have two switches 6500 in vss each with a JOINT module, I need to examine other configurations of this situation?

    The VACL I'll put is:

    ACL_IPS extended IP access list

    allow an ip

    !

    VLAN-access plan VACL_IPS 10

    corresponds to the IP ACL_IPS

    action forward

    !

    VLAN filter VACL_IPS vlan-list of 30, 40, 50, 100

    !

    detection of intrusion switch 1 module 4-port data 1 capture allowed - vlan 30,40,50,100

    switch 1 capture of data-port 1 intrusion detection module 4

    1 switch intrusion detection module 4 data ports 1 autostate include

    !

    detection of intrusion switch 2 module 4-port data 1 capture allowed - vlan 30,40,50,100

    switch 2 capture of data-port 1 intrusion detection module 4

    2 switch intrusion detection module 4 data ports 1 autostate include

    Thanks for the help.

    The METHOD didn't need special orders to inspect the traffic in Promiscious mode.

    You'll want to put your JOINT management on a local VIRTUAL network interfaces to talk with them:

    detection of intrusion management access module 4-port - vlan 99

    Use the switch "transfer the capture:

    VLAN-access plan VACL_IPS 10

    corresponds to the IP ACL_IPS

    action before capture

    Get rid of the spaces between your numbers VLAN

    VLAN filter VACL_IPS vlan-list 30,40,50,100

    If you put two IDSMs in the same chassis, you will need to decide how to divide traffic between them. You can assign different VLAN to each METHOD.

    -Bob

Maybe you are looking for