01-21-2005 11:10 AM - edited 03-10-2019 01:14 AM
I have a PIX-514 configured for SSH. I also have a 4210 IDS on the internal network. At one time I know the IDS would shun (using the firewall). I believe that if you do a show ssh sessions on the firewall you will always see the IDS as connected. I changed the passwords on the PIX this morning and I went into the IDS and changed the password under Logical Devices. I connected back to the PIX and did a show ssh sessions. The only thing it reported was my session. If I repeat the command I will sometimes see the ip address of the sensor but the state is 2 and the encryption and username are empty.
Am I right in thinking that the IDS should have a connection at all times? I know ssh is working because I can connect to the PIX from my desktop. I know the passwords are right because I've checked and rechecked them. I even did a sho config from the command line of the IDS and it displays the passwords in plain text so I know the passwords are correct. Any ideas or things to check? Thanks.
01-21-2005 12:28 PM
I solved my own problem. I regenerate the known host-key for my PIX and right after that the IDS established the connection. Not sure what happened but its working now.
01-21-2005 12:51 PM
from the sesnor do a "show stat net" and look for the pix. Does the state say "Active" or "Connecting"?
You can also do a show events on the sensor and then stop/start blocking using idm. You should see any errors nac is having.
Try that for starters.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide