This is a discussion on RE: [snort-users] Blocking with a PIX within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------_=_NextPart_001_01C43763.EED7DFC8 Content-Type: text/plain; charset="us-ascii&...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
This is a multi-part message in MIME format.
------_=_NextPart_001_01C43763.EED7DFC8 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable The shuns won't show up in the rulebase. Connect to the pix, get to an enable prompt, and type 'sh shun' to see if the shuns are being applied. It should show a list of the current shuns in place. =20 Andrew Hutchinson - Network Security Vanderbilt University Medical Center (615) 936-2856 -----Original Message----- From: snort-users-admin@lists.sourceforge.net [mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of d.deboni@edexter.it Sent: Tuesday, May 11, 2004 8:45 AM To: snort-users@lists.sourceforge.net Subject: [snort-users] Blocking with a PIX =09 =09 Hi to everyone,=20 =09 I've configured snort with snortsam to block attacks from the outside.=20 It worked all perfectly when I tried it on a Cisco Router.=20 =09 But now I need to do that with a Cisco PIX.=20 =09 Here's the snortsam.conf file:=20 =09 accept 127.0.0.1=20 pix <PIXIP> <TELNETPASSWORD> <ENABLEPASSWORD>=20 =09 When I try to launch both snort and snortsam I see these messages, and it seems that snortsam is applying the rules on the pix:=20 =09 Checking for existing state file: Present. Reading State=20 Starting to listen for Snort alerts.=20 Accepted connection from 127.0.0.1=20 Accepted connection from 127.0.0.1=20 Adding sensor 127.0.0.1 to list.=20 Blocking host <IP> completely for 7200 seconds=20 Accepted connection from 127.0.0.1=20 Blocking host <IP> completely for 7200 seconds=20 Accepted connection from 127.0.0.1=20 Blocking host <IP> completely for 7200 seconds=20 =09 and so on...=20 =09 By the way if I look at the Pix configuration there are no rules applied.=20 I know that the PIX Plugin use the shun command to block IP, and if i try it manually on the Pix it works.=20 =09 I've tried to disable telnet for the Snort/Snortsam server on the Pix to see if Snortsam works anyway. If I do that SnortSam says it can't connect to Pix.=20 So it seems that SnortSam "works"....=20 =09 Thanks for help=20 =09 =09 Davide De Boni =09 Email: d.deboni@edexter.it =09 e.Dexter S.P.A. C.so Risorgimento 5 28823 Ghiffa (VB) ITALIA Tel +39.0323.407733 Fax +39.0323.53558 ------_=_NextPart_001_01C43763.EED7DFC8 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD><TITLE>Message</TITLE> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR></HEAD> <BODY> <DIV><SPAN class=3D133562414-11052004><FONT face=3DArial color=3D#0000ff = size=3D2>The=20 shuns won't show up in the rulebase. Connect to the pix, get to an = enable=20 prompt, and type 'sh shun' to see if the shuns are being applied. = It=20 should show a list of the current shuns in place.</FONT></SPAN></DIV> <DIV><SPAN class=3D133562414-11052004><FONT face=3DArial color=3D#0000ff = size=3D2></FONT></SPAN> </DIV> <DIV><SPAN class=3D133562414-11052004><!-- Converted from text/plain = format --> <P><FONT size=3D2>Andrew Hutchinson - Network Security<BR>Vanderbilt = University=20 Medical Center<BR>(615) 936-2856<BR></FONT></P></SPAN></DIV> <BLOCKQUOTE style=3D"MARGIN-RIGHT: 0px"> <DIV></DIV> <DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr = align=3Dleft><FONT=20 face=3DTahoma size=3D2>-----Original Message-----<BR><B>From:</B>=20 snort-users-admin@lists.sourceforge.net=20 [mailto:snort-users-admin@lists.sourceforge.net] <B>On Behalf Of=20 </B>d.deboni@edexter.it<BR><B>Sent:</B> Tuesday, May 11, 2004 8:45=20 AM<BR><B>To:</B> snort-users@lists.sourceforge.net<BR><B>Subject:</B>=20 [snort-users] Blocking with a PIX<BR><BR></FONT></DIV><BR><FONT=20 face=3Dsans-serif size=3D2>Hi to everyone,</FONT> <BR><BR><FONT = face=3Dsans-serif=20 size=3D2>I've configured snort with snortsam to block attacks from the = outside.</FONT> <BR><FONT face=3Dsans-serif size=3D2>It worked all = perfectly when=20 I tried it on a Cisco Router.</FONT> <BR><BR><FONT face=3Dsans-serif = size=3D2>But=20 now I need to do that with a Cisco PIX.</FONT> <BR><BR><FONT = face=3Dsans-serif=20 size=3D2>Here's the snortsam.conf file:</FONT> <BR><BR><FONT = face=3Dsans-serif=20 size=3D2>accept 127.0.0.1</FONT> <BR><FONT face=3Dsans-serif = size=3D2>pix=20 <PIXIP> <TELNETPASSWORD> <ENABLEPASSWORD></FONT>=20 <BR><BR><FONT face=3Dsans-serif size=3D2>When I try to launch both = snort and=20 snortsam I see these messages, and it seems that snortsam is applying = the=20 rules on the pix:</FONT> <BR><BR><FONT face=3Dsans-serif = size=3D2>Checking for=20 existing state file: Present. Reading State</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>Starting to listen for Snort alerts.</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>Accepted connection from 127.0.0.1</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>Accepted connection from 127.0.0.1</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>Adding sensor 127.0.0.1 to list.</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>Blocking host <IP> completely for 7200 seconds</FONT> = <BR><FONT=20 face=3Dsans-serif size=3D2>Accepted connection from 127.0.0.1</FONT> = <BR><FONT=20 face=3Dsans-serif size=3D2>Blocking host <IP> completely for = 7200=20 seconds</FONT> <BR><FONT face=3Dsans-serif size=3D2>Accepted = connection from=20 127.0.0.1</FONT> <BR><FONT face=3Dsans-serif size=3D2>Blocking host = <IP>=20 completely for 7200 seconds</FONT> <BR><BR><FONT face=3Dsans-serif = size=3D2>and so=20 on...</FONT> <BR><BR><FONT face=3Dsans-serif size=3D2>By the way if I = look at the=20 Pix configuration there are no rules applied.</FONT> <BR><FONT = face=3Dsans-serif=20 size=3D2>I know that the PIX Plugin use the shun command to block IP, = and if i=20 try it manually on the Pix it works.</FONT> <BR><BR><FONT = face=3Dsans-serif=20 size=3D2>I've tried to disable telnet for the Snort/Snortsam server on = the Pix=20 to see if Snortsam works anyway. If I do that SnortSam says it can't = connect=20 to Pix.</FONT> <BR><FONT face=3Dsans-serif size=3D2>So it seems that = SnortSam=20 "works"....</FONT> <BR><BR><FONT face=3Dsans-serif size=3D2>Thanks for = help</FONT>=20 <BR><BR><FONT face=3Dsans-serif size=3D2><BR>Davide De = Boni<BR><BR>Email:=20 d.deboni@edexter.it<BR><BR>e.Dexter S.P.A.<BR>C.so Risorgimento = 5<BR>28823=20 Ghiffa (VB)<BR>ITALIA<BR>Tel +39.0323.407733<BR>Fax=20 +39.0323.53558</FONT></BLOCKQUOTE></BODY></HTML> =00 ------_=_NextPart_001_01C43763.EED7DFC8-- ------------------------------------------------------- This SF.Net email is sponsored by Sleepycat Software Learn developer strategies Cisco, Motorola, Ericsson & Lucent use to deliver higher performing products faster, at low TCO. http://www.sleepycat.com/telcomwpreg...rom=osdnemail3 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |