HP-UX Host Intrusion Detection System Version 4.1 Administrator's Guide

Table F-2 System Manager Error Messages (continued)
ActionMeaningError Message
Either select a specific IP
address or 0.0.0.0. If you
select a specific IP address, it
must correspond to the
network interface for the
network connecting the
administration and agent
systems. If 0.0.0.0 is selected,
the administration system can
be connected to agent systems
that are reachable on any of the
administration’s network
interfaces.
On your administration system,
edit /opt/ids/bin/idsgui.
Set the INTERFACE variable to
either the IP address you have
chosen, or to 0.0.0.0.
For example, change the
INTERFACE line to read
INTERFACE=1.2.3.4”.
When you are done, reset the
file permissions to u=rx (500).
This host (hostname) has
multiple network addresses. The
INTERFACE configuration
setting in idsgui must specify the
hostname/IP address of the
interface to listen for connections
from agents or 0.0.0.0 to listen on
all interfaces.
On each agent system, edit
/etc/opt/ids/ids.cf.If the
INTERFACE variable in step 2
was set to a specific IP address,
set the REMOTEHOST
parameter to the same value. If
the INTERFACE variable in
step 2 was set to 0.0.0.0, set the
REMOTEHOST parameter to
the IP address of the
administration system with a
network interface connected to
the same network that the
agent interface is connected to.
For example, change the
REMOTEHOST line to read
“REMOTEHOST 1.2.3.4”. When
you are done, reset the file
permissions to u=r (400). If the
agent is currently running,
instruct the agent to reread
ids.cf. See “Forcing Active
Agent to Reread Configuration
File” (page 239).
System Manager Messages 265