Re: [fw-wiz] Cisco Pix-IDS Blocking

From: Dario Calia (dcalia_at_cisco.com)
Date: 06/09/03

  • Next message: DJ Gregor: "Re: [fw-wiz] [Administrivia] Moderation, etc."
    To: woodse@vra.net
    Date: Mon, 09 Jun 2003 13:14:07 -0700
    
    

    Hello,

    You will need a more recent IDS image. The PIX introduced
    a change which warranted a matching change on the IDS
    software. Have a look @ CSCdx55215 for the corresponding
    IDS enhancement/change.

    Thanks, Dario

    At 11:22 AM 6/9/2003 -0400, woodse@vra.net wrote:
    >Hello,
    >
    >I could really use some help. I've recently deployed a Cisco Pix 506
    >with ver 6.3 and Cisco 4210 IDS ver. 3.1. I have setup the 4210 to
    >connect to the Pix via SSH for blocking using shun commands but it's
    >not working. I've confirmed that the 4210 is logging in but it just
    >doesn't seem to send the shun commands.
    >
    >Has anyone else ever experienced this problem? I would appricate any
    >help on this matter.
    >
    >Everett Woods
    >
    >_______________________________________________
    >firewall-wizards mailing list
    >firewall-wizards@honor.icsalabs.com
    >http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: DJ Gregor: "Re: [fw-wiz] [Administrivia] Moderation, etc."

    Relevant Pages

    • Re: Monitoring Servers
      ... An IDS system on the outside of your PIX is rather pointless (especially if ... it's the "IDS" that comes with the PIX), since you're not seeing what gets ... honeypot inside the network, make sure it's a dark host (has no legitimate ...
      (microsoft.public.security)
    • Re: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls
      ... From what i know looking PIXen inside and outside, IDS module is packet capture ... > Cisco is marketing the ASA 5500 appliances as PIX, VPN Concentrator, Secure ...
      (Firewall-Wizards)
    • Cisco pix IDS feature question
      ... We have cisco pix 515E now we want to turn on the IDS feature to block ... IDS has about 60 signatures for example detecting Fyn scans. ... when those attacks passed before enabling the IDS? ... if its dropped packets and the traffic sure passed throw the ...
      (comp.dcom.sys.cisco)
    • RE: [fw-wiz] Thoughts on the new Cisco ASA 5500 firewalls
      ... Cisco is marketing the ASA 5500 appliances as PIX, VPN Concentrator, Secure ... IDS, and network anti-virus in a single box. ...
      (Firewall-Wizards)