This is a discussion on [snort-users] Blocking with a PIX within the Snort forums, part of the System Security and Security Related category; This is a multipart message in MIME format. --=_alternative 004B84F2C1256E91_= Content-Type: text/plain; charset="US-ASCII" Hi ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a multipart message in MIME format.
--=_alternative 004B84F2C1256E91_= Content-Type: text/plain; charset="US-ASCII" Hi to everyone, I've configured snort with snortsam to block attacks from the outside. It worked all perfectly when I tried it on a Cisco Router. But now I need to do that with a Cisco PIX. Here's the snortsam.conf file: accept 127.0.0.1 pix <PIXIP> <TELNETPASSWORD> <ENABLEPASSWORD> When I try to launch both snort and snortsam I see these messages, and it seems that snortsam is applying the rules on the pix: Checking for existing state file: Present. Reading State Starting to listen for Snort alerts. Accepted connection from 127.0.0.1 Accepted connection from 127.0.0.1 Adding sensor 127.0.0.1 to list. Blocking host <IP> completely for 7200 seconds Accepted connection from 127.0.0.1 Blocking host <IP> completely for 7200 seconds Accepted connection from 127.0.0.1 Blocking host <IP> completely for 7200 seconds and so on... By the way if I look at the Pix configuration there are no rules applied. I know that the PIX Plugin use the shun command to block IP, and if i try it manually on the Pix it works. I've tried to disable telnet for the Snort/Snortsam server on the Pix to see if Snortsam works anyway. If I do that SnortSam says it can't connect to Pix. So it seems that SnortSam "works".... Thanks for help Davide De Boni Email: d.deboni@edexter.it e.Dexter S.P.A. C.so Risorgimento 5 28823 Ghiffa (VB) ITALIA Tel +39.0323.407733 Fax +39.0323.53558 --=_alternative 004B84F2C1256E91_= Content-Type: text/html; charset="US-ASCII" <br><font size=2 face="sans-serif">Hi to everyone,</font> <br> <br><font size=2 face="sans-serif">I've configured snort with snortsam to block attacks from the outside.</font> <br><font size=2 face="sans-serif">It worked all perfectly when I tried it on a Cisco Router.</font> <br> <br><font size=2 face="sans-serif">But now I need to do that with a Cisco PIX.</font> <br> <br><font size=2 face="sans-serif">Here's the snortsam.conf file:</font> <br> <br><font size=2 face="sans-serif">accept 127.0.0.1</font> <br><font size=2 face="sans-serif">pix <PIXIP> <TELNETPASSWORD> <ENABLEPASSWORD></font> <br> <br><font size=2 face="sans-serif">When I try to launch both snort and snortsam I see these messages, and it seems that snortsam is applying the rules on the pix:</font> <br> <br><font size=2 face="sans-serif">Checking for existing state file: Present. Reading State</font> <br><font size=2 face="sans-serif">Starting to listen for Snort alerts.</font> <br><font size=2 face="sans-serif">Accepted connection from 127.0.0.1</font> <br><font size=2 face="sans-serif">Accepted connection from 127.0.0.1</font> <br><font size=2 face="sans-serif">Adding sensor 127.0.0.1 to list.</font> <br><font size=2 face="sans-serif">Blocking host <IP> completely for 7200 seconds</font> <br><font size=2 face="sans-serif">Accepted connection from 127.0.0.1</font> <br><font size=2 face="sans-serif">Blocking host <IP> completely for 7200 seconds</font> <br><font size=2 face="sans-serif">Accepted connection from 127.0.0.1</font> <br><font size=2 face="sans-serif">Blocking host <IP> completely for 7200 seconds</font> <br> <br><font size=2 face="sans-serif">and so on...</font> <br> <br><font size=2 face="sans-serif">By the way if I look at the Pix configuration there are no rules applied.</font> <br><font size=2 face="sans-serif">I know that the PIX Plugin use the shun command to block IP, and if i try it manually on the Pix it works.</font> <br> <br><font size=2 face="sans-serif">I've tried to disable telnet for the Snort/Snortsam server on the Pix to see if Snortsam works anyway. If I do that SnortSam says it can't connect to Pix.</font> <br><font size=2 face="sans-serif">So it seems that SnortSam "works"....</font> <br> <br><font size=2 face="sans-serif">Thanks for help</font> <br> <br><font size=2 face="sans-serif"><br> Davide De Boni<br> <br> Email: d.deboni@edexter.it<br> <br> e.Dexter S.P.A.<br> C.so Risorgimento 5<br> 28823 Ghiffa (VB)<br> ITALIA<br> Tel +39.0323.407733<br> Fax +39.0323.53558</font> --=_alternative 004B84F2C1256E91_=-- ------------------------------------------------------- This SF.Net email is sponsored by Sleepycat Software Learn developer strategies Cisco, Motorola, Ericsson & Lucent use to deliver higher performing products faster, at low TCO. http://www.sleepycat.com/telcomwpreg...rom=osdnemail3 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |