HP ProCurve Threat Management Solution Implementation Guide 2009-05

3-55
HP ProCurve Network Immunity Manager with a Third-Party IDS/IPS
Step 2: Detect Threats
Figure 3-54. Sample Network with Cisco 4200 Series Sensor Operating as an IDS
The procedure covers only the setup of the sensor for IDS operation; NIM’s response to the
threat is covered in “Step 3: Respond to Threats” on page 3-126.
To set up the sensor as an IDS, complete the following steps:
1. Manually set up local mirroring in PCM+ as instructed in “Set Up Local Mirroring” on
page 3-25.
2. Check the Cisco 4200 Series Sensor’s configuration.
a. Click Configuration in the toolbar.
b. If necessary, click the Interfaces tab in the navigation bar to display the interface
configuration options.
c. Click Interfaces to configure an interface for IDS. In the example configuration, the
GigabitEthernet0/1 and GigabitEthernet0/2 interfaces are reserved for use with IPS;
GigabitEthernet0/3 i-s used for the IDS. (You may have different interfaces on your
sensor.)
d. Select the appropriate interface.
e. Click Enable on the right to enable it.
f. Click Apply.