Remote Data Exchange Protocol
Remote Data
Exchange Protocol
As of the Cisco IDS 4.0 software, PostOffice Protocol is no
longer used for communication between console and IDS sensor devices. Instead,
Cisco implements the Remote Data Exchange Protocol (RDEP), which is a
proprietary HTTP and XML-based configuration and event generation messaging
system. It employs "pull" mechanisms for event collection and analysis.
With Cisco IDS 4.0 Sensors, management and control functionality
used an SSL-based XML messaging format for communication. Alarm notification
from sensors still requires acknowledgement as it did with PostOffice Protocol.
The RDEP protocol is TCP-based however, so it employs the reliability routines
present in TCP as well. Because the transport uses Secure Socket Layer to
encrypt communications, the protocol is secure.
The RDEP protocol is simpler and easier to manage than the
PostOffice Protocol. It uses well-known TCP port 443 by default for quick
firewall rule set modification. When configuring RDEP communications,
administrators will need to provide a device name for the sensor, whether they
intend to use encryption for communication, and on what port they wish to run
the service.
211 times read
|
|
|
Did you enjoy this article?
(total 0 votes)
|