
5-67
Cisco Wireless LAN Controller Configuration Guide
OL-13826-01
Chapter 5 Configuring Security Solutions
Configuring IDS
Step 6 To save your settings, enter this command:
save config
Step 7 To view the IDS sensor configuration, enter one of these commands:
• show wps cids-sensor summary
• show wps cids-sensor detail index
The second command provides more information than the first.
Step 8 To obtain debug information regarding IDS sensor configuration, enter this command:
debug wps cids enable
Note If you ever want to delete or change the configuration of a sensor, you must first disable it by entering
config wps cids-sensor disable index. To then delete the sensor, enter config wps cids-sensor delete
index.
Viewing Shunned Clients
When an IDS sensor detects a suspicious client, it alerts the controller to shun this client. The shun entry
is distributed to all controllers within the same mobility group. If the client to be shunned is currently
joined to a controller in this mobility group, the anchor controller adds this client to the dynamic
exclusion list, and the foreign controller removes the client. The next time the client tries to connect to
a controller, the anchor controller rejects the handoff and informs the foreign controller that the client is
being excluded. See Chapter 11 for more information on mobility groups.
You can view the list of clients that the IDS sensors have identified to be shunned through either the GUI
or the CLI.
Using the GUI to View Shunned Clients
Follow these steps to view the list of clients that the IDS sensors have identified to be shunned using the
controller GUI.
Step 1 Click Security > Advanced > CIDS > Shunned Clients. The CIDS Shun List page appears (see
Figure 5-37).
Figure 5-37 CIDS Shun List Page
Komentarze do niniejszej Instrukcji