04-20-2005 09:31 PM - edited 02-21-2020 12:05 AM
Hello,
I am just wondering if it is possible to configure PIX firewall (515E, 6.3) to block viruses entering my network? I have not seen any commands related to this on the PIX config guide.
Can anyone throw some light?
Thank you,
Mo
04-20-2005 11:31 PM
Hi Mohan,
PIX firewall inspects only layer 4 ports and denies if anything is blocked.. incase a standard port is open and the vulnarable/virus traffic is on that port, PIX will not block it.. it wont do anything on application layer inspection.. You can have an IDS parallel to the PIX, which can sniff these traffic and block if necessary.. even with this combination, u cant 100 % be sure that you are virus free..
version 7.0 of pix has a lot of application inspection engines defined.. i havent tested that.. you can have a look at the release notes of V7.0
Raj
04-21-2005 03:03 AM
Hi Raj,
Thank you for your response. Also, I think the IDS capabilities available on PIX can be used to detect some viruses, based on the available signatures.
Thank you,
Mo
04-21-2005 04:08 AM
Raj, is absolutly right. The PIX does not filter out viruses !
Even the IDS Signatures in version 6.3.x does not inspect that. There are new functionalities to do so called NAC - Network Access Control in Routers and Switches that will do this in the near future but not jet in the PIX.
http://www.cisco.com/ca/forum/pdf/sec-03.pdf
With PIX OS 7.0 were introduced some more application layer inspection that can block P2P and other application as MSN.
By the way here is a list of the IDS Signatures in version 7.0 and even there is nothing.
sincerely
Patrick
04-21-2005 07:53 PM
Little correction - NAC means NETWORK ADMISSION CONTROL (NAC). There is a Post on that topic on General Security Group !
ASK THE EXPERT- NETWORK ADMISSION CONTROL (NAC)
sincerely
Patrick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide