RE: CISCO IDS Packet capture

From: Matt Vaughan (mcv_at_OceanShipholdings.com)
Date: 04/06/04

  • Next message: Strand, John: "RE: CISCO IDS Packet capture"
    Date: Tue, 6 Apr 2004 09:44:07 -0500
    To: "Strand, John" <John.Strand@mms.gov>, <focus-ids@securityfocus.com>
    
    

    Hi John,

    You can configure specific signature types to be captured. You can open
    them up in something like Ethereal after downloading them from IDM (IDS
    web interface).
     

    -----Original Message-----
    From: Strand, John [mailto:John.Strand@mms.gov]
    Sent: Friday, April 02, 2004 7:36 AM
    To: focus-ids@securityfocus.com
    Subject: CISCO IDS Packet capture

    Hello All,

    Does anyone know how to enable some level of packet capture and logging
    on the CISCO IDS system (the newer version which interfaces with
    CiscoWorks and can run on Win2K)? I have hunted through the CISCO
    provided PDF's and their a little on the light side. I also have hit the
    usual suspects, google, CISCO groups, etc..

    Thanks in advance for any help.

    js

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Strand, John: "RE: CISCO IDS Packet capture"

    Relevant Pages

    • Re: Testing IDS with tcpreplay
      ... different things than with Metasploit or similar tools. ... I would argue that you are testing the IDS to figure out if it will be ... instance of the target then replay makes sense. ... Which is why you should capture the same exploit being used ...
      (Focus-IDS)
    • RE: IDS deployment on a Cat6500 series & which Snort box?
      ... This limitation also exists with VACL Capture when running in IOS. ... The sniffing interface of an IDS should not have an IP address, ...
      (Focus-IDS)
    • RE: Ciscos IDS Vulnerabilities
      ... The ability of Cisco's IDS to detect attack signatures is NOT affected by ... Lets take RPC buffer overflows for example, ADMmutate ... Cisco IDS will alarm on both the original attack and the ...
      (Focus-IDS)
    • RE: Reports from Cisco IDS
      ... Cisco IDS reporting features. ... Subject: Reports from Cisco IDS ... The Ciscoworks VMS plugin is very new. ...
      (Focus-IDS)
    • RE: Recommending an IDS system
      ... I never worked with ISS IDS appliance before so I can't really comment on ... Subject: Recommending an IDS system ... We have been using Cisco IDS systems for a number of years and recently ...
      (Security-Basics)