<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDS integration with the PIX Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151917#M609576</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Instructions for sensor and PIX  basic configuration can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid23" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid23&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instructions for sensor and PIX SSH configuration can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid16" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid16&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the sensor to connect to the PIX via telnet when&lt;/P&gt;&lt;P&gt;using the PIX inside interface, otherwise you must use SSH.&lt;/P&gt;&lt;P&gt;SSH with 3des encryption is supported in version 3.0 or later&lt;/P&gt;&lt;P&gt;sensors for PIX connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Caveat: If you want to use telnet with a version 6.2.1 or later PIX, or if &lt;/P&gt;&lt;P&gt;you want to use SSH  with des encryption on any PIX, then you will &lt;/P&gt;&lt;P&gt;need a patch for your sensor. If so, open a TAC case and request &lt;/P&gt;&lt;P&gt;the latest engineering build of nr.managed.  Reference  &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:stleary@cisco.com"&gt;stleary@cisco.com&lt;/A&gt; for any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Feb 2003 04:06:59 GMT</pubDate>
    <dc:creator>stleary</dc:creator>
    <dc:date>2003-02-12T04:06:59Z</dc:date>
    <item>
      <title>IDS integration with the PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151914#M609572</link>
      <description>&lt;P&gt;I am reading the Release Notes for Cisco Intrusion Detection System Sensor Version 3.0(1)S4, and I have stumbled on the new features of this version that it claims Integration with the PIX Firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you implement this? What kind of integration does it offer?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151914#M609572</guid>
      <dc:creator>rolalo</dc:creator>
      <dc:date>2020-02-21T06:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: IDS integration with the PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151915#M609573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IDS Sensor has a feature called shun/blocking  (originally known as shun, but over time has become known as blocking).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the IDS detects an attack it can be configured to connect to another Cisco device (through telnet or ssh with username/passwords), and then reconfigure the device to shun/block the ipaddress of the attacker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When using IDS blocking feature with a Cisco router the sensor will telnet to the router and create an ACL which will deny the ip address of the attacker.&lt;/P&gt;&lt;P&gt;When using IDS blocking feature with a Pix the sensor will telnet/ssh to the pix and execute a special "shun &lt;IPADDRESS&gt;" command on the pix.  The Pix then blocks packets to or from that ip address on all of it's interfaces.&lt;/IPADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Feb 2003 21:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151915#M609573</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2003-02-11T21:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: IDS integration with the PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151916#M609574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply,  Any template or configuration that I could follow?&lt;/P&gt;&lt;P&gt;I am using an IDS 4210 software version 3.01(S4).&lt;/P&gt;&lt;P&gt;and CSPM 2.3.1i.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Feb 2003 02:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151916#M609574</guid>
      <dc:creator>rolalo</dc:creator>
      <dc:date>2003-02-12T02:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: IDS integration with the PIX Firewall</title>
      <link>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151917#M609576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Instructions for sensor and PIX  basic configuration can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid23" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid23&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instructions for sensor and PIX SSH configuration can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid16" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids8/13870_01.htm#xtocid16&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can configure the sensor to connect to the PIX via telnet when&lt;/P&gt;&lt;P&gt;using the PIX inside interface, otherwise you must use SSH.&lt;/P&gt;&lt;P&gt;SSH with 3des encryption is supported in version 3.0 or later&lt;/P&gt;&lt;P&gt;sensors for PIX connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Caveat: If you want to use telnet with a version 6.2.1 or later PIX, or if &lt;/P&gt;&lt;P&gt;you want to use SSH  with des encryption on any PIX, then you will &lt;/P&gt;&lt;P&gt;need a patch for your sensor. If so, open a TAC case and request &lt;/P&gt;&lt;P&gt;the latest engineering build of nr.managed.  Reference  &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:stleary@cisco.com"&gt;stleary@cisco.com&lt;/A&gt; for any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Feb 2003 04:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-integration-with-the-pix-firewall/m-p/151917#M609576</guid>
      <dc:creator>stleary</dc:creator>
      <dc:date>2003-02-12T04:06:59Z</dc:date>
    </item>
  </channel>
</rss>

