I have a test ids executing a shun to a PIX over ssh. We see the signature fire, the sensor status shows the ip address of the offending host being shunned, and a time limit of 15 minutes which we have set. On the PIX, we see the ids sensor logged into it, but no shun command is ever executed. Doing a show event error on the sensor shows the following error:
evError: eventId=1055761573999175903 severity=error
originator:
hostId: test
appNAme: nac
appInstanceId: 1099
time: 2004/11/23 13:12:09 2004/11/23 09:12:09 EDT
errorMessage: name=errSystemError ERROR: Initilization timeout at device IP [pix ip address]
I have tried deleting and re-adding the blocking device and get the same thing. Any suggestions would be appreciated.