cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
302
Views
0
Helpful
1
Replies

sensor fails to execute shun on PIX

shawn.posthumus
Level 1
Level 1

I have a test ids executing a shun to a PIX over ssh. We see the signature fire, the sensor status shows the ip address of the offending host being shunned, and a time limit of 15 minutes which we have set. On the PIX, we see the ids sensor logged into it, but no shun command is ever executed. Doing a show event error on the sensor shows the following error:

evError: eventId=1055761573999175903 severity=error

originator:

hostId: test

appNAme: nac

appInstanceId: 1099

time: 2004/11/23 13:12:09 2004/11/23 09:12:09 EDT

errorMessage: name=errSystemError ERROR: Initilization timeout at device IP [pix ip address]

I have tried deleting and re-adding the blocking device and get the same thing. Any suggestions would be appreciated.

1 Reply 1

nkhawaja
Cisco Employee
Cisco Employee

Hi,

what is the sensor version. What is PIX version. What method you are using for SHUN? Telnet or SSH?

Review Cisco Networking for a $25 gift card