Re: CISCO IDS Packet capture

From: James Fields (jvfields_at_tds.net)
Date: 04/07/04

  • Next message: Alex Arndt: "RE: CISCO IDS Packet capture"
    To: "Strand, John" <John.Strand@mms.gov>, <focus-ids@securityfocus.com>
    Date: Tue, 6 Apr 2004 20:32:47 -0400
    
    

    For each signature on a newer Cisco sensor, you have the ability to turn on
    and off the features called log, reset, and block. Log is the choice that
    causes it to capture. You then get the capture off the sensor using the web
    interface on the sensor. It will be in pcap format, readable with Ethereal
    or other analyzers that can read that format.

    ----- Original Message -----
    From: "Strand, John" <John.Strand@mms.gov>
    To: <focus-ids@securityfocus.com>
    Sent: Friday, April 02, 2004 9:35 AM
    Subject: CISCO IDS Packet capture

    >
    > Hello All,
    >
    > Does anyone know how to enable some level of packet capture and logging on
    > the CISCO IDS system (the newer version which interfaces with CiscoWorks
    and
    > can run on Win2K)? I have hunted through the CISCO provided PDF's and
    their
    > a little on the light side. I also have hit the usual suspects, google,
    > CISCO groups, etc..
    >
    > Thanks in advance for any help.
    >
    >
    > js
    >
    > --------------------------------------------------------------------------
    -
    >
    > --------------------------------------------------------------------------
    -
    >

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Alex Arndt: "RE: CISCO IDS Packet capture"

    Relevant Pages

    • RE: CISCO IDS Packet capture
      ... The Cisco Secure Intrusion Detection Sensor runs on a modified ... Stopping cids turns off the intrusion detection function of the sensor. ... Subject: CISCO IDS Packet capture ...
      (Focus-IDS)
    • Re: Signature Tuning on Cisco IDS
      ... Signature Tuning on Cisco IDS ... For Cisco that would going above 100Mbit of traffic or so. ... need to periodicly redo your filter settings. ... Initially run the sensor in a raw, ...
      (Focus-IDS)
    • RE: CISCO IDS Packet capture
      ... > Subject: CISCO IDS Packet capture ... > Does anyone know how to enable some level of packet capture and logging on ... The feature you're referring to is known as "IP Logging" in Cisco's ...
      (Focus-IDS)
    • Signature Tuning on Cisco IDS
      ... Signature Tuning on Cisco IDS ... The sensor is running the latest version of OS, ...
      (Focus-IDS)
    • Re: Fwd: Re: IDS evaluation
      ... I'm a Product Manager for Cisco IDS. ... Cisco IDS 4235 & 4250 have been shipping for a while now. ... >Dragon are still vaporware at this time. ...
      (Focus-IDS)