Lab 11.1.10 Implement Intrusion Detection [WLOs: 1, 2, 3, 4, 5] [CLOs: 1, 2, 3]
Explanation
In this lab, your task is to:
- Enable the IPS on the LAN and DMZ interface.
- Manually update the IPS signature using C:\signatures\sbips000018.bin
- Use the following credentials to configure the NSA to automatically update the signature in the future:
- Username: mary.r.brown
- Password: Upd@teN0w (0 is a zero)
- Set the IPS policies to detect and prevent all known threats.
Complete this lab as follows:
- Enable IPS as follows:
- In the Security Appliance Configuration utility, select IPS.
- Under IPS Enable, select Enable IPS Protection for LAN.
- Select Enable IPS Protection for DMZ.
- Select Apply.
- Update the IPS signature as follows:
- Under Manual Signature Updates, select Browse.
- Browse to and select C:\Signatures\SBIPS000018.bin.
- Select Open.
- Select Upload.
- Refresh the page to update the IPS Signatures status.
- Select Automatically Update Signatures.
- In the Cisco.com User Name field, enter mary.r.brown.
- In the Password field, enter Upd@teN0w (0 is a zero).
- Select Apply.
- Configure IPS policies as follows:
- In the left menu, select IPS Policy.
- For each IPS Category, select Detect and Prevent.
- Select Apply.
Comments
Post a Comment