cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
4
Helpful
3
Replies

IEV monitor the PIX

r.perera
Level 1
Level 1

Hi, Pls some one help me with, how to configure PIX 6.3 to be monitord by IEV v4.1

Best Regards

Ranji

3 Replies 3

sachinraja
Level 9
Level 9

Hello Ranji

As far as I'm concerned, IDS Event Viewer (IEV) is used to view the events & statistics of a IDS. I dont think you can monitor anything with respect to a PIX here.. normally you have the firewall MC on the ciscoworks, where you can monitor the pix firewall events....

Raj

Hi Sachinraj,

I'm reading for IDS exam and it says it is very possible to monitor IDS massages from IEV but I can't find any info at Cisco docs.

Best regards

Ranji

The IEV 4.1 communicates to the end device using RDEP (Remote Data Exchange Protocol).

The only devices supporting RDEP servers are the 4.1 Sensor Appliances and Modules.

So IEV 4.1 can not be used to monitor the IDS alerts being generated by either the Pix Firewalls or IOS Routers.

NOTE: The older 3.1 IEV communicated to the end device using the postoffice protocol.

Version 3.1 Sensor Appliances, and Modules supported the postoffice protocol.

ALSO the IOS Routers with IDS functionality also supported the postoffice protocol, so IEV 3.1 could monitor IOS Routers producing IDS alerts.

BUT the Pix only produces IDS alerts as syslog messages and so can not be monitored by IEV 3.1 or IEV 4.1 (or IEV 4.0).

On the other hand, there is another product Security Monitor (also known as SecMon) that is part of the VPN and Security Management Solution (VMS) that is often mistaken with IEV.

SecMon supports the postoffice protocol, RDEP, and syslog for monitoring the end devices.

So SecMon CAN monitor IDS alerts from a Pix Firewall, IOS Router, and the Sensor Appliances and Modules.

Review Cisco Networking for a $25 gift card