ISDM2 with FWSM configuration example

Hi there,
We're trying to implement isdm2 as inline mode integrated with fwsm module. We have two vlans on the switch: vlan 30 is responsible to take care the outside interface of the lab context of fwsm while vlan 40 is responsible from the inside interface. How can i implement a correct configuration in order to use isdm2 to inspect traffic ? There are several documents on the net, but i'm really confused with them and no one is clear enough.
P.S: At the moment we're using isdm2 in promiscous mode with the following configuration :
intrusion-detection module 3 data-port 1 capture
intrusion-detection module 3 data-port 1 capture allowed-vlan 30
Thanks in advance.

The IDSM2 is supported in inline mode, provided that the switch has a sup720 running 12.2(18)SXE (or later) or a sup32 running 12.2(18)SXF (or later).
Refer these link for configuration doc:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids12/cliguide/cliidsm2.htm
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids10/hwguide/index.htm

Similar Messages

  • VLAN query with Cisco configuration example

    Dear List,
    I was wondering if there is an error on the Cisco documentation below.
    The diagram and config shows the LWAPs attached to the switch on vlan 5, but the trunk to the WLC is pruning vlan 5.
    If this is correct, how can the LWAPs speak LWAPP with the WLC?
    The suggested config is a few lines below the diagram.
    Thanks for any feedback.
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080665cdf.shtml#dia
    Chris.

    The AP's management is on vlan 5, so there is not reason to have vlan 5 allowed on the trunk to the wlc.  Only interfaces that are configured on the WLC should be allowed.
    Management, AP-Manager, and any dynamic interfaces... service-port can be included but shouldn't be routable.
    Hope this explains it... if not let me know:)

  • PCK :: Configuration Example: Message Exchange

    Hello experts,
    I has a problem with the configuration example from the SAP help to the partner Connectivity Kit.
    http://help.sap.com/saphelp_nw04/helpdata/en/8b/895e407aa4c44ce10000000a1550b0/frameset.htm
    I have built up everything like in the description - two PCK (party_A and party_B) and XI (party_XI).
    In message monitor of the first PCK (party A) stands that a message is explained successfully and second with error.
    Status: waiting.
    Details -
    audit log:
    Success Delivering to channel: message_an_xi
    Error Exception caught by adapter framework: String index out of range: 0
    Error Delivery of the message to the application using connection AFW failed, due to: String index out of range:0.
    Message Data:
    Error Category XI_J2EE_ADAPTER_ENGINE
    Error Code GENERAL_ERROR
    Wo und wie muss ich Fehler beseitigen?
    Has already explained jemang this example?
    Is it executable?
    Thank's.
    Regards,
    Alex

    Hi Zoran
    While using BPM as well you will need to have communication channels.
    BPM - > BAPI request.
    BAPI response -> BPM
    both sender and receiver channels are required for you.
    1.Demand for a material is send via HTTP to XI
    2.XI does a material availability check to the SAP system
    3.A material reservation has to be done if there are any materials available in the stock (inventory) to the SAP system
    4.If there is no material available a purchase order to a supplier (no SAP) has to be done via FTP
    5.Parallel to the purchase order a purchase order confirmation is send to the the SAP system.
    6.The supplier sends a purchase order confirmation to XI
    7.The XI sends a purchase order confirmation to the SAP system
    If i understood your requirement correctly and you want to use BPM. You need to do following in BPM
    Receivestep1(receive HTTP post) -> transform1(mapping to BAPI request) ->send step1(Send BAPI request to SAP) -> Receivestep2 (Receive BAPI response from SAP) -> Transform2 (Map BAPI response to File)-> send2(File post to non SAP supplier)-> Receive3(receive purchase order confirmation)-> transform3(map to SAP purchase order confirmation)-> send3(Purchase order confirmation to sap)
    You need no of channels
    1.Receive 1 - (HTTP)
    2.Send1/Receive2 - (RFC)
    3.Send2 - (FTP)
    4. Receive3( HTTP or FTP)
    5. For purchase order confirmation.
    Thanks
    Gaurav

  • Doubts in XI basics..help me with some practical examples

    hi friends,
              I am new to SAP XI have some basic doubts. Answer my questions with some practical examples.
      1. what is meant by "Business System" and what is difference between client,customer,Business partner,3rd party
      2.If a small company already using some systems like Oracle or peopleSoft,if it wants to use SAP products then what steps it has to follow.
    3. SAP system means a SERVER?
    4.SAPWebAs means a server software?
    5.R/3 system comes under SAP system?
    6.XI is also one of the SAP  module..how it relates to other modules.
    7.In one organization which is using SAP modules,each module will be load in separate servers?
    8.PO(purchase order) means just looks like one HTML file..customer will fill the form and give it.like this,Combination of many files like this is one SAP module.Is it right assumption..?if so,then what is speciality SAP?
       I have an theoretical knowledge about IR and ID and SLD.what are general business transactions happens in any business ?(like who will send cotation,PO)  give some practical example for what actually happens in business?..who will do what?and what XI will do?

    Hi Murali,
    <u><b> 1.Business System</b></u>
      Business systems are logical systems that function as senders or receivers  within the SAP Exchange Infrastructure(XI).
    Before starting with any XI interface,the Business systems involved has to be configured in SLD(The SLD acts as the central information provider for all installed system components in your system landscape.)
    business system and technical system in XI
    <u><b>2.Third Party</b></u>
    http://help.sap.com/saphelp_nw04/helpdata/en/09/6beb170d324216aaf1fe2feb8ed374/frameset.htm
    eg.For the SAP system a  Bank would be a third-party which would be involved in interfaces involving exchange of data(Bill Payment by customer).
    <u><b>3.XI(Exchange Infrastructure)</b></u>
      It enables you to connect systems from different vendors (non-SAP and SAP) in different versions and implemented in different programming languages (Java, ABAP, and so on) to each other.
    Eg.If an interface involves Purchase Order sent from SAP system to the vendor(Non-SAP system)then,the vendor might expect a file.But the Data is in the IDOC(intermediate document) form with the SAP system.Here XI does the work of mapping the IDOC fields and the File fields and sends it to the vendor in the form of a file.
    In short,always the scene is Sender-XI-Receiver.
    The Sender and the Receiver depends upon the Business you are dealing with.
    <u><b>4.Business Partner</b></u>
    A person, organization, group of persons, or group of organizations in which a company has a business interest.
    This can also be a person, organization or group within this company.
    Examples:
    Mrs. Lisa Miller
    Maier Electricals Inc.
    Purchasing department of Maier Electricals Inc.
    <u><b>5.Client</b></u>
    http://help.sap.com/saphelp_nw04/helpdata/en/6c/a74a3735a37273e10000009b38f839/frameset.htm
    <u><b>6.SAP System</b></u>
    http://help.sap.com/saphelp_nw04/helpdata/en/33/1f4f40c3fc0272e10000000a155106/frameset.htm
    <u><b>7.SAP WebAS</b></u>
    https://www.sdn.sap.com/irj/sdn/advancedsearch?query=sapwebapplication+server&cat=sdn_all
    As you are a beginner, I understand you musn’t be aware of where to search what.
    For all details search out in http://help.sap.com
    And sdn(key in keyword in Search tab).
    You will get list of forums,blogs,documentation answering all your queries.

  • Configuration management (LO-CM) used with Variant configuration (LO-VC)

    Hi
    I am new to SAP, working with Variant configuration (LO-VC).
    I wish to enforce configuration management during development of a new Variant configurator.
    Would Configuration management (LO-CM) work together with Variant configuration (LO-VC)?
    My expectation is that SAP Configuration management (LO-CM) will work similar to solutions like e.g. MsVisualSourceSafe, SubVersion, CVS, IBM/Rational ClearCase etc. in the software development domain.
    best regards Henrik

    Hi Amber
    Thanks a lot for answer, and please apologize my late response.
    I am not confused by the term 'configuration', being used in two different meanings.
    (1) Variant configuration (VC) is the dicipline of creating product variants by making a set of choises from the characteristics describing the product. A complete and consistent set of choises is a 'configuration'.
    (2) Configuration Management in the 'traditional' software development meaning: Software Configuration Management (SCM). E.g. Microsoft VisualSourceSafe, IMB/Rational ClearCase, Subversion etc. are examples of tools used for the kind of SCM I wish to apply to VC models.
    My confusion is whether the SAP CM that I can read about in the SAP online help, is similar to traditional SCM, and whether it can be applied to VC models.
    I wish to apply SCM to a VC model. All the objects that together make up the VC model may then each exist in various versions (version control). A complete set of the objects (in a given version) make up a configuration of the VC model.
    What is achieved is : you can control the development of VC model in just the same way that all serious software is under the control of SCM. This will allow an evolution of the VC model, like e.g. version 1.0 is released in January, then version 1.1 is released in June. A major upgrade of the model may become version 2.0 in December etc. The 'source code' (the objects) of each of the versions can be retrieved at any time from the SCM system. Also with SCM several developers may work on the same VC model at the same time, and merge their individual work into the same model.
    This is very different from todays VC model development. In todays VC model development, only one version exists, that is 'todays version'. Any change to the model is released immediately, and you can undo model changes only if you remember what it was like a little while ago.
    We do develop and test VC models in one SAP system, and then move them to the production system. This is however still very far from the benefits of SCM.
    best regards
    Henrik Saugbjerg

  • How to start a systemd with certain configuration options?

    Hello,
    I do not understand what wiki page at arch that can help me to understand how I can start a daemon with certain configuration options. I know I can start with
    # systemctl enable unit
    , but for example, if I whanted to start "xboxdrv" with the option [--mimic-xpad-wireless --silent], or any other custom options I might need. I presume it can be done simple by dropping a .conf file somewhere, but I do not follow what wiki page that adress this - if it at all is possible?
    Regards
    Martin

    Hello,
    I followed the drop in option now in https://wiki.archlinux.org/index.php/Sy … n_snippets
    I tried to copy the whole xboxdrv.service and replace the ExecStart, and also only with ExecStart, like this:
    [Service]
    ExecStart=
    ExecStart= ExecStart = /usr/bin/xboxdrv -D -c /etc/default/xboxdrv --mimic-xpad-wireless --silent
    The drop in examples above is in: /etc/systemd/system/xboxdrv.service.d/override.conf
    Reatarting
    I then made sure the new .conf file was loaded by:
    # systemctl daemon-reload
    # systemctl restart xboxdrv
    # system status xboxdrv
    Result
    In both cases, the service fails to restart and I recive this error
    xboxdrv.service has more than one ExecStart= setting, which is only allowed for Type=oneshot services. Refusing.
    Anyone know how I can start "xboxdrv" with my custom options "--mimic-xpad-wireless --silent" using this drop in function for systemd?
    Regards
    Martin
    Last edited by onslow77 (2015-02-01 18:27:31)

  • Wlsm with fwsm question

    Hi
    Question I have is related to the following setup. WLSM and access points (L3 roaming)incorporated into 6500 with FWSM. The FWSM is firewalling 2 wireless networks. Access points have BVI on seperate subnet with subinterfaces on fastethernet defining vlans for 2 ssid's. BVI subnet has HSRP address for default gateway on the access points. The issue is as part of a security audit it was discovered that wireless clients were recieving HSRP traffic even though they should be completely seperate from the rest of the network via the FWSM. IS this normal or am I missing something?
    Thanks

    In relevance to this issue, you have mentioned that " The FWSM is firewalling 2 wireless networks". So, can you send me the firewall configuration?. Also, send me the network topology. These two information will be really helpful for furher analysis.

  • Backup or redundant ISP with FWSM and security contexts...

    Hello guys,
    I am in a middle of a dessign problem. We have 2 ISP, and we have a FWSM running multiple contexts, my context that is receiving all the static translations for all my published servers is the one where i want to configure default gateway tracking (so it can go out to an "outside2" interface in case the primary fails) and use the second ISP link for internet access and static nat. Just the exact way the ASA works.
    I am not quite sure it works with FWSM.
    Thanks a lot!
    emilio

    Hello Emilio,
    You cannot configure SLA monitoring on the FWSM at this moment.
    Maybe in the future this great feature will be added to this modules.
    I know the 6500 supports it so you can try to set it up there.
    Regards,
    Julio

  • DMVPN DUAL HUB SINGLE CLOUD CONFIGURATION EXAMPLE

    Hi,
    I am looking for a simple configuration for a dmvpn network running eigrp with two hubs on a single cloud.
    Do i just create two nhs entries, nhrp map entries, and two multicast entries on the spoke router tunnel interfaces?  And on the hub routers add a delay on the tunnel interfaces for the one i prefer to be the secondary?
    I am looking for confirmation and any other tweaks i need to make. i cant seem to find any examples.
    Thanks in advance!!

    Thanks Paul, I have looked over this design guide as this was the fist place i went.  however, i cannot find a configuration example for dual hub/single cloud.
    i see the high level design and know you can do it.   but it doesnt show what the configuration would look like...unless i am just reading over it.
    Thanks

  • Placing a new button with WD configuration

    Hi experts,
    I'm trying to place a new button in Web Dynpro component /SAPSRM/WDC_UI_BEV_CA, with component configuration /SAPSRM/WDCC_FPM_UI_BEV_RFQ_CA.
    I've already placed a button on toolbar block and also added a new FPM event ID NEW_EVENT.
    When I debug the WD application FPM_OIF_COMPONENT, I'm able to detect that the new event is raised. But now I want to add some code for opening a new window. Where should I place this code? Please note that I need 1 parameter from the WD application (OBJECT_ID).
    Can you help me?
    Thanks in advance.
    André Sousa

    Hi,
    Thanks for your answer.
    I was not able to understand if I need to change the standard WD component FPM_OIF_COMPONENT.
    If not how does the developed WD know that should be started? Does this component need to instantiated somehow?
    Could you please give me more detail regarding what I need to do to implement this need?
    Example:
    Where to place the io_event and how to instantiate the developed WD?
    Thanks a lot!
    Cheers,
    André Sousa

  • Need Configuration example for DS-LITE ( Tunneling IPv4-IPv6)+NAT44.

    Hi,
    I need to understand DS-LITE with configuration example. Can anyone please help me out?
    Regards,
    RA

    Hi Rahul,
    DS-Lite is only supported on the CGSE in CRS and on the ISM in the ASR9k. Here is a sample config that might help you to understand.
    RP/0/RSP0/CPU0:router(config)#
    interface te0/0/0/0
    ipv6 add 2001:db8:ff00::1/64
    interface te0/1/0/0
    ipv4 add 192.168.100.1/24
    interface ServiceApp61
    ipv6 address 2001:db8:1::1/64
    service cgn demo service-type ds-lite
    interface ServiceApp41
    ipv4 address 192.168.1.1 255.255.255.252
    service cgn demo service-type ds-lite
    service cgn demo
    service-type ds-lite dslite-1
    map address-pool x.y.z.0/24
    aftr-tunnel-endpoint-address 2001:db8:ffff::1
    address-family ipv4
       interface ServiceApp42
    address-family ipv6
       interface ServiceApp41
    router static
    address-family ipv4 unicast
    x.y.z.0/24 ServiceApp42
    address-family ipv6 unicast
    2001:db8:ffff::1/128 ServiceApp41
    regards

  • Can I find NX7K VDC design/configuration examples?

    We have a couple of NX7K that we plan to have 2 VDC on each. So the 7K can function as a virtual core switch and virtual distribution switch. I have read about some VDC concepts but have not been able to find a detailed VDC design and configurations example document from Cisco sites. If any one has seen one, can you share that with me?
    A few subjects I like to find good examples:
    Connection in between ports in different VDC;
    Management connectivity to each VDC;
    Routing config between VDC.
    Thanks

    Hello
    The best source that would cover all the relevant VPC details would be the design guide available here:
    http://www.cisco.com/en/US/products/ps9670/products_implementation_design_guides_list.html
    The first 4 chapters are lots to read but it very good
    Hth
    Sent from Cisco Technical Support iPhone App

  • ImportToFlow with other configuration

    Due to another helpful reply in this forum I finally have a single line editable textfield working.
    Problem now is that I still need to set configuration options. I dont really fully understand the framework as yet.
    Here is my code.
    var config:Configuration = new Configuration();
    config.manageEnterKey = false;
    var textFlow:TextFlow = new TextFlow(config);
    textFlow.interactionManager = new EditManager();
    textFlow.fontFamily = "Arial";
    textFlow.fontSize = 20;
    textFlow.lineBreak = "explicit";
    textFlow.flowComposer.addController(new DisplayObjectContainerController(sprite,width,height));
    textFlow.flowComposer.updateAllContainers();
    However I need to also set some other options on my field.
    Firstly I need to set the initial text of the field. Before I was doing this " var textFlow:TextFlow = TextFilter.importToFlow(text, TextFilter.PLAIN_TEXT_FORMAT);" but now I cant seem to figure out how to use the importToFlow along with the configuration.
    Secondly. I need to restrict the field to only allow 50 characters (Due to database limits etc). How do I do this?
    Are there some good demo resources that show code in practise in common situations we would have normaly used an old standard "TextField" for.
    I've been reading the http://livedocs.adobe.com/labs/textlayout/ docs but there seem to be few simple examples for newbies to this area. Unless you sort of know where to go its all a bit confusing.
    Thanks in advance.

    I was having trouble doing that due to the example that I copied from here
    http://livedocs.adobe.com/labs/textlayout/flashx/textLayout/conversion/ImportExportConfigu ration.html#textFlowConfiguration
    My code was
    var imExConfig:ImportExportConfiguration = new ImportExportConfiguration();
    var config:Configuration = imExConfig.defaultConfiguration.textFlowConfiguration;
    config.manageTabKey = false;
    config.manageEnterKey = false;
    var textFlow:TextFlow = TextFilter.importToFlow(text, TextFilter.PLAIN_TEXT_FORMAT, imExConfig);
    but I was getting a "1119: Access of possibly undefined property defaultConfiguration through a reference with static type flashx.textLayout.conversion:ImportExportConfiguration." error... The docs say that defaultConfiguration is a valid property... so thats wierd.
    Anyway afetr lots of messing around I got it to work this way
    var config:Configuration = new Configuration();
    config.manageTabKey = false;
    config.manageEnterKey = false;
    var imExConfig:ImportExportConfiguration = new ImportExportConfiguration();
    imExConfig.textFlowConfiguration = config;
    var textFlow:TextFlow = TextFilter.importToFlow(text, TextFilter.PLAIN_TEXT_FORMAT, imExConfig);
    and that is now allowing me to use my config with the importToFlow.

  • ACE in bridge mode with FWSM as gateway

    our design
    FWSM--vlan 7--ACE-vlan 8---servers with default gateway as FWSM
    originally there were no plans of servers looking to load balance traffic when they wanted to communicate each other. now there is a need this
    since ACE is in bridge mode, there are no ip address to VLAN configured on it and cant do source NAT
    what we want servers in serverfarm A can contact a single ip which can be load balanced and traffic to be sent to serverfarm B. both serverfarms reside in vlan 8 and ace is in bridge. with VLAN not having IP how can we get this working. we were looking to create a policy on ACE with an ip address in vlan 8 and then do a source NAT to send the traffic to serverfarm 7.
    with FWSM as the default gateway, by enabling permit intra traffic , it doesnt work because the command routes the traffic, dont think will send the traffic back to the same vlan
    e.g static (inside,outside) 10.7.0.1 10.7.8.13 and allow intra traffic.
    so when a machine 10.7.8.11 pings 10.7.0.1 it goes to the FWSM but fwsm doesnt look for 10.7.8.13
    with ACE in bridge and FWSM doing above how to get around. can something be done on ACE in bridge mode with source NAT
    Thanks

    First, why don't you have an ip in your ACE vlan ?
    Then, for traffic hitting a vip, we can do source nating even in bridge mode.
    But if the vip is not an ip in vlan 8, your server will anyway send the traffic to the FWSM and ACE will first bridge the request.
    The FWSM should then send the request back to ACE (not sure how this can be done).
    So the request from the server will actually hit the vip on vlan 7 (not vlan 8).
    So your policy-map with client nat must be on vlan 7.
    Another option would be to configure a static route on the server to point the vip to the ACE vlan 8 ip address (which you should have configured).
    In this case, the policy-map will have to be in vlan 8 with client-nat.
    Gilles.

  • Problem using Implementing Remote Panel Security with a Login Example Guide

    I'm having issues implementing a Remote Panel protected by username and password using this NI guide:
    Implementing Remote Panel Security with a Login Example
    Remotepanellogin.zip
    After login process using Login.vi, if the user has the right password, his IP will be included in the Webserver allowed access list and the user can open the web site which hosts the Main.vi. Ok.
    But if the user doesn't have the password, his IP will be denied!
    Here is the problem: Will his IP be denied at all including Login.vi? 
    I can't block access to Login.vi because even if the user entered a wrong password, he can still try login again....
    How can I configure a type of Allowed and Denied table using Webserver properties? For example:
    IP: 10.0.0.2 - Login.vi (allowed) - Main.vi (allowed) -> User entered a right password
    IP: 10.0.0.3 - Login.vi (allowed) - Main.vi (denied) -> User entered a wrong password
    Note: Login.vi must be visible and accessible always.
    These are the Implementing Remote Panel Security with a Login Example instructions:
    After you configure the VIs with the Web Publishing Tool, browse to the Remote Panel Login VI and run it. When this VI runs, LabVIEW gives remote panel access to all users, but they can view and control only this VI.
    If a user successfully logs in by supplying the Username of NI and password of labview (both are case sensitive) then LabVIEW gives remote panel access to the IP address specified in the Remote Panel Login VI only. That user can then browse to and run the Main VI.
    Thanks in advance!
    APrado
    Message Edited by APrado on 04-01-2009 08:21 AM

    I'm thinking about using the option Reentrant Execution (VI property > Category > Execution).
    Could anyone help me?
    Thanks.

Maybe you are looking for