参考:http://www.netemu.cn/bbs/thread-9735-1-1.html,但是其中有些问题,做了修改,帖子中有我的注释。
1.现状:
VMWare版的IPS5.0,只有三块网卡,第一块网卡为command口,其余两个为sensor口,无法测试interface pair与杂合模式是否能同时使用,因为至少需要3个sensor口;两个sensor口到时可以测试一个接口采用VLAN pair,另外一个接口采用杂合模式。
2.添加一块sensor网卡的步骤:
A.VMWare中虚拟机添加一块网卡,与本地一块loopbak网卡桥接
B.关闭IPS虚拟机,修改vmx文件:
添加一行:ethernet3.virtualDev = "e1000"
C.再次打开虚拟机,以service帐号登录,并且su - root
root帐号密码和service的帐号密码一致
D.修改/usr/cids/idsRoot/etc/interface.conf文件:
①slot的pci-device分别为17和20,跨度为4,网卡的总数量
[models/IDS-4215/slots/1]
# lower slot
pci-bus=1
pci-device=17
[models/IDS-4215/slots/2
# upper slot
pci-bus=2
pci-device=20
②网卡的pci-device从17依次到20
[models/IDS-4215/interfaces/1]
# built-in 10/100 TX mgmt interface, Intel 82559ER
# was eth1 (int1) in 4.x
# rightmost connector on front panel
# labeled "Ethernet 1" on panel
name-template=Management0/0
#pci-bus=0
pci-device=17
pci-function=0
vendor-id=0x8086
device-id=0x100f
type=ge
mgmt-capable=yes
default-admin-state=enable
on-backplane=yes
[models/IDS-4215/interfaces/2]
# built-in 10/100 TX sensing interface, Intel 82559ER
# was eth0 (int0) in 4.x
# leftmost connector labeled "Ethernet 0"
name-template=GigabitEthernet0/1
#pci-bus=0
pci-device=18
pci-function=0
vendor-id=0x8086
device-id=0x100f
type=ge
sensing-capable=yes
tcp-reset-capable=yes
default-admin-state=enabled
[models/IDS-4215/interfaces/3]
name-template=GigabitEthernet0/2
#pci-bus=0
pci-device=19
pci-function=0
vendor-id=0x8086
device-id=0x100f
type=ge
sensing-capable=yes
tcp-reset-capable=yes
default-admin-state=enabled
[models/IDS-4215/interfaces/4]
# rightmost interface on optional 1 x 4-FE card:
# on secondary bus of pci-pci bridge on the interface card
# was eth5 (int5) in 4.x
#pci-bus=0
name-template=GigabitEthernet0/3
pci-device=20
pci-function=0
vendor-id=0x8086
device-id=0x100f
type=ge
sensing-capable=yes
tcp-reset-capable=yes
default-admin-state=enabled