<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to config PIX IDS feature? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270257#M593987</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is what i have got configured&lt;/P&gt;&lt;P&gt;ip audit name IDS_info info action alarm&lt;/P&gt;&lt;P&gt;ip audit name IDS_attack attack action reset&lt;/P&gt;&lt;P&gt;ip audit interface outside IDS_info&lt;/P&gt;&lt;P&gt;ip audit interface outside IDS_attack&lt;/P&gt;&lt;P&gt;ip audit info action alarm reset&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can also perform following:&lt;/P&gt;&lt;P&gt;CityID3(config)# show ip audit count&lt;/P&gt;&lt;P&gt;Signature                               outside Global&lt;/P&gt;&lt;P&gt;1000 I Bad IP Options List              0       0&lt;/P&gt;&lt;P&gt;1001 I Record Packet Route              0       0&lt;/P&gt;&lt;P&gt;1002 I Timestamp                        0       0&lt;/P&gt;&lt;P&gt;1003 I Provide s,c,h,tcc                0       0&lt;/P&gt;&lt;P&gt;1004 I Loose Source Route               0       0&lt;/P&gt;&lt;P&gt;1005 I SATNET ID                        0       0&lt;/P&gt;&lt;P&gt;1006 I Strict Source Route              0       0&lt;/P&gt;&lt;P&gt;1100 A IP Fragment Attack               0       0&lt;/P&gt;&lt;P&gt;1102 A Impossible IP Packet             0       0&lt;/P&gt;&lt;P&gt;1103 A IP Teardrop                      0       0&lt;/P&gt;&lt;P&gt;2000 I ICMP Echo Reply                  20      20&lt;/P&gt;&lt;P&gt;2001 I ICMP Unreachable                 56395   56395&lt;/P&gt;&lt;P&gt;2002 I ICMP Source Quench               2664    2664&lt;/P&gt;&lt;P&gt;2003 I ICMP Redirect                    388     388&lt;/P&gt;&lt;P&gt;2004 I ICMP Echo Request                5079    5079&lt;/P&gt;&lt;P&gt;2005 I ICMP Time Exceed                 9117    9117&lt;/P&gt;&lt;P&gt;2006 I ICMP Parameter Problem           2       2&lt;/P&gt;&lt;P&gt;2007 I ICMP Time Request                0       0&lt;/P&gt;&lt;P&gt;2008 I ICMP Time Reply                  0       0&lt;/P&gt;&lt;P&gt;2009 I ICMP Info Request                0       0&lt;/P&gt;&lt;P&gt;2010 I ICMP Info Reply                  0       0&lt;/P&gt;&lt;P&gt;2011 I ICMP Address Mask Request        0       0&lt;/P&gt;&lt;P&gt;2012 I ICMP Address Mask Reply          0       0&lt;/P&gt;&lt;P&gt;2150 A Fragmented ICMP                  0       0&lt;/P&gt;&lt;P&gt;2151 A Large ICMP                       157     157&lt;/P&gt;&lt;P&gt;2154 A Ping of Death                    0       0&lt;/P&gt;&lt;P&gt;3040 A TCP No Flags                     72      72&lt;/P&gt;&lt;P&gt;3041 A TCP SYN &amp;amp; FIN Flags Only         50      50&lt;/P&gt;&lt;P&gt;3042 A TCP FIN Flag Only                4       4&lt;/P&gt;&lt;P&gt;3153 A FTP Improper Address             11      11&lt;/P&gt;&lt;P&gt;3154 A FTP Improper Port                0       0&lt;/P&gt;&lt;P&gt;4050 A Bomb                             3       3&lt;/P&gt;&lt;P&gt;4051 A Snork                            12      12&lt;/P&gt;&lt;P&gt;4052 A Chargen                          0       0&lt;/P&gt;&lt;P&gt;6050 I DNS Host Info                    0       0&lt;/P&gt;&lt;P&gt;6051 I DNS Zone Xfer                    0       0&lt;/P&gt;&lt;P&gt;6052 I DNS Zone Xfer High Port          0       0&lt;/P&gt;&lt;P&gt;6053 I DNS All Records                  0       0&lt;/P&gt;&lt;P&gt;6100 I RPC Port Registration            0       0&lt;/P&gt;&lt;P&gt;6101 I RPC Port Unregistration          0       0&lt;/P&gt;&lt;P&gt;6102 I RPC Dump                         0       0&lt;/P&gt;&lt;P&gt;6103 A Proxied RPC                      0       0&lt;/P&gt;&lt;P&gt;6150 I ypserv Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6151 I ypbind Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6152 I yppasswdd Portmap Request        0       0&lt;/P&gt;&lt;P&gt;6153 I ypupdated Portmap Request        0       0&lt;/P&gt;&lt;P&gt;6154 I ypxfrd Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6155 I mountd Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6175 I rexd Portmap Request             0       0&lt;/P&gt;&lt;P&gt;6180 I rexd Attempt                     0       0&lt;/P&gt;&lt;P&gt;6190 A statd Buffer Overflow            0       0&lt;/P&gt;&lt;P&gt;CityID3(config)#&lt;/P&gt;&lt;P&gt;sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Mar 2004 15:40:07 GMT</pubDate>
    <dc:creator>ciscoacs</dc:creator>
    <dc:date>2004-03-15T15:40:07Z</dc:date>
    <item>
      <title>How to config PIX IDS feature?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270256#M593986</link>
      <description>&lt;P&gt;What signature enabale on PIX? &lt;/P&gt;&lt;P&gt;I must enable first?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270256#M593986</guid>
      <dc:creator>adul</dc:creator>
      <dc:date>2020-02-21T07:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to config PIX IDS feature?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270257#M593987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is what i have got configured&lt;/P&gt;&lt;P&gt;ip audit name IDS_info info action alarm&lt;/P&gt;&lt;P&gt;ip audit name IDS_attack attack action reset&lt;/P&gt;&lt;P&gt;ip audit interface outside IDS_info&lt;/P&gt;&lt;P&gt;ip audit interface outside IDS_attack&lt;/P&gt;&lt;P&gt;ip audit info action alarm reset&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can also perform following:&lt;/P&gt;&lt;P&gt;CityID3(config)# show ip audit count&lt;/P&gt;&lt;P&gt;Signature                               outside Global&lt;/P&gt;&lt;P&gt;1000 I Bad IP Options List              0       0&lt;/P&gt;&lt;P&gt;1001 I Record Packet Route              0       0&lt;/P&gt;&lt;P&gt;1002 I Timestamp                        0       0&lt;/P&gt;&lt;P&gt;1003 I Provide s,c,h,tcc                0       0&lt;/P&gt;&lt;P&gt;1004 I Loose Source Route               0       0&lt;/P&gt;&lt;P&gt;1005 I SATNET ID                        0       0&lt;/P&gt;&lt;P&gt;1006 I Strict Source Route              0       0&lt;/P&gt;&lt;P&gt;1100 A IP Fragment Attack               0       0&lt;/P&gt;&lt;P&gt;1102 A Impossible IP Packet             0       0&lt;/P&gt;&lt;P&gt;1103 A IP Teardrop                      0       0&lt;/P&gt;&lt;P&gt;2000 I ICMP Echo Reply                  20      20&lt;/P&gt;&lt;P&gt;2001 I ICMP Unreachable                 56395   56395&lt;/P&gt;&lt;P&gt;2002 I ICMP Source Quench               2664    2664&lt;/P&gt;&lt;P&gt;2003 I ICMP Redirect                    388     388&lt;/P&gt;&lt;P&gt;2004 I ICMP Echo Request                5079    5079&lt;/P&gt;&lt;P&gt;2005 I ICMP Time Exceed                 9117    9117&lt;/P&gt;&lt;P&gt;2006 I ICMP Parameter Problem           2       2&lt;/P&gt;&lt;P&gt;2007 I ICMP Time Request                0       0&lt;/P&gt;&lt;P&gt;2008 I ICMP Time Reply                  0       0&lt;/P&gt;&lt;P&gt;2009 I ICMP Info Request                0       0&lt;/P&gt;&lt;P&gt;2010 I ICMP Info Reply                  0       0&lt;/P&gt;&lt;P&gt;2011 I ICMP Address Mask Request        0       0&lt;/P&gt;&lt;P&gt;2012 I ICMP Address Mask Reply          0       0&lt;/P&gt;&lt;P&gt;2150 A Fragmented ICMP                  0       0&lt;/P&gt;&lt;P&gt;2151 A Large ICMP                       157     157&lt;/P&gt;&lt;P&gt;2154 A Ping of Death                    0       0&lt;/P&gt;&lt;P&gt;3040 A TCP No Flags                     72      72&lt;/P&gt;&lt;P&gt;3041 A TCP SYN &amp;amp; FIN Flags Only         50      50&lt;/P&gt;&lt;P&gt;3042 A TCP FIN Flag Only                4       4&lt;/P&gt;&lt;P&gt;3153 A FTP Improper Address             11      11&lt;/P&gt;&lt;P&gt;3154 A FTP Improper Port                0       0&lt;/P&gt;&lt;P&gt;4050 A Bomb                             3       3&lt;/P&gt;&lt;P&gt;4051 A Snork                            12      12&lt;/P&gt;&lt;P&gt;4052 A Chargen                          0       0&lt;/P&gt;&lt;P&gt;6050 I DNS Host Info                    0       0&lt;/P&gt;&lt;P&gt;6051 I DNS Zone Xfer                    0       0&lt;/P&gt;&lt;P&gt;6052 I DNS Zone Xfer High Port          0       0&lt;/P&gt;&lt;P&gt;6053 I DNS All Records                  0       0&lt;/P&gt;&lt;P&gt;6100 I RPC Port Registration            0       0&lt;/P&gt;&lt;P&gt;6101 I RPC Port Unregistration          0       0&lt;/P&gt;&lt;P&gt;6102 I RPC Dump                         0       0&lt;/P&gt;&lt;P&gt;6103 A Proxied RPC                      0       0&lt;/P&gt;&lt;P&gt;6150 I ypserv Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6151 I ypbind Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6152 I yppasswdd Portmap Request        0       0&lt;/P&gt;&lt;P&gt;6153 I ypupdated Portmap Request        0       0&lt;/P&gt;&lt;P&gt;6154 I ypxfrd Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6155 I mountd Portmap Request           0       0&lt;/P&gt;&lt;P&gt;6175 I rexd Portmap Request             0       0&lt;/P&gt;&lt;P&gt;6180 I rexd Attempt                     0       0&lt;/P&gt;&lt;P&gt;6190 A statd Buffer Overflow            0       0&lt;/P&gt;&lt;P&gt;CityID3(config)#&lt;/P&gt;&lt;P&gt;sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Mar 2004 15:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270257#M593987</guid>
      <dc:creator>ciscoacs</dc:creator>
      <dc:date>2004-03-15T15:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to config PIX IDS feature?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270258#M593988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you your help so much&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2004 02:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-config-pix-ids-feature/m-p/270258#M593988</guid>
      <dc:creator>adul</dc:creator>
      <dc:date>2004-03-16T02:31:56Z</dc:date>
    </item>
  </channel>
</rss>

