05-13-2003 02:41 PM - edited 03-09-2019 03:16 AM
I'm trying to configure blocking with PIX. I have configured the IDS with the PIX parameters in order to make the blocking, but in the Manual Blocking page of the DeviceManager in the field "Net Device Status" it shows password_sent, it never shows active.
I can make telnet from the ids to the pix succesfuly.
Any idea?
Thanks.
05-13-2003 07:16 PM
What ids version are you using? In 3.1 there is a known issue connecting to pix using version 6.2.1 with telnet. If you use ssh and 3des it will work fine. Upgrading to 4.0 will also solve the problem.
05-14-2003 02:08 PM
Thanks for your help.
With ssh the blocking is working. But now, the shunned IP never is un-shunned from the firewall.
I have configured ICMP echo request signature to block for 3 minutes. When the ping starts the source IP is blocked, 3 minutes later the manual blocking page shows when the block ends and the IP disappears from the blocked IPs, but in the PIX it is still shunned, I can see this using show shun statistics command in the firewall.
When the test is made with manual blocking of IDS-DM it works fine.
The IDS version is 3.1(3)S43, PIX version 6.2(2).
Thanks.
05-14-2003 07:50 PM
When the next shun happens, are they both listed using "show shun statistics"? So basically the shun list keeps increasing. Can you unshun them manually on the pix with the unshun command?
05-15-2003 04:59 AM
Check in your nr.managed errors file for recent errors. This is the
file /usr/nr/var/errors.managed.(pid). The only reason I know of
for a shun to fail to be removed is if the sensor loses contact with
the pix. That problem, and any other problems should be reported
in the errors log. Contact can be lost due to transient network
conditions. But eventually when contact is reestablished, the
shun shun be removed. Also, edit the files /usr/nr/etc/managed.conf.
If it contains any entries for permant shuns, you can delete them
from the file, and then restart the sensor.
05-15-2003 07:23 AM
The /usr/nr/var/errors.managed.(pid) file doesn't show errors related with the IP address that should be unshunned. Also, there aren't lines in /usr/nr/etc/managed.conf containing entries related with time.
In the file /usr/nr/var/log.200305150934 there is a message reporting the shunning of the IP and a message reporting the unshun of the ip.
05-15-2003 07:16 AM
Yes they are both listed. And the only way to unblock is typing "clear shun" in the pix.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide