Solved

IDS on PIX 506e

Posted on 2006-10-26
6
298 Views
Last Modified: 2013-11-16
Dear Experts

We have the following commands on our PIX 506e FW

logging on
logging timestamp
logging trap informational
logging host inside 192.168.1.7
<snip>
ip audit info action alarm
ip audit attack action alarm

In order to check for Intrusion Detection, can anyone tell me what I should be looking for on the Kiwi Syslog server?

Thx
0
Comment
Question by:Dilan77
  • 4
  • 2
6 Comments
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17812115
PIX 506E do not have IDS inbuilt into it. Can't do! Only higher end models.

Cheers,
Rajesh
0
 
LVL 32

Accepted Solution

by:
rsivanandan earned 250 total points
ID: 17812133
On the other hand if you want to look at normal firewall actions, this will help you get acquainted with PIX messages;

http://www.cisco.com/en/US/customer/products/sw/secursw/ps2120/products_system_message_guide_chapter09186a00800891ec.html#25608

Cheers,
Rajesh
0
 
LVL 2

Author Comment

by:Dilan77
ID: 17812159
That's weird....there is an IDS section on the PDM! It's set to log events.
0
Now Available: Firebox Cloud for AWS and FireboxV

Firebox Cloud brings the protection of WatchGuard’s leading Firebox UTM appliances to public cloud environments. It enables organizations to extend their security perimeter to protect business-critical assets in Amazon Web Services (AWS).

 
LVL 32

Expert Comment

by:rsivanandan
ID: 17812215
Yeah, it is a Java Client and common for all, but this Model doesn't have it. If you go for Integrated devices (ASA 5xxx series), only those have IDS functionality.

Right now, Cisco has only 3 platforms for IDS/IPS;

1. IOS IPS -> On a router

2. Firewall IPS -> On ASA Series

3. IDS Appliance -> 4200 series appliances.

Cheers,
Rajesh
0
 
LVL 2

Author Comment

by:Dilan77
ID: 17812438
Ok, thanks Rajesh....
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17813204
No Problem.

Cheers,
Rajesh
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Have you experienced traffic destined through a Cisco ASA firewall disappears and you do not know if the traffic stops in the firewall or somewhere else? The solution is the capture feature. This feature was released in 6.2(1) and works in all firew…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question