RE: [snort-users] Blocking with a PIX

This is a discussion on RE: [snort-users] Blocking with a PIX within the Snort forums, part of the System Security and Security Related category; This is a multi-part message in MIME format. ------_=_NextPart_001_01C43763.EED7DFC8 Content-Type: text/plain; charset="us-ascii&...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-11-2004
Hutchinson, Andrew
 
Posts: n/a
Default RE: [snort-users] Blocking with a PIX

This is a multi-part message in MIME format.

------_=_NextPart_001_01C43763.EED7DFC8
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

The shuns won't show up in the rulebase. Connect to the pix, get to an
enable prompt, and type 'sh shun' to see if the shuns are being applied.
It should show a list of the current shuns in place.
=20
Andrew Hutchinson - Network Security
Vanderbilt University Medical Center
(615) 936-2856


-----Original Message-----
From: snort-users-admin@lists.sourceforge.net
[mailto:snort-users-admin@lists.sourceforge.net] On Behalf Of
d.deboni@edexter.it
Sent: Tuesday, May 11, 2004 8:45 AM
To: snort-users@lists.sourceforge.net
Subject: [snort-users] Blocking with a PIX
=09
=09

Hi to everyone,=20
=09
I've configured snort with snortsam to block attacks from the
outside.=20
It worked all perfectly when I tried it on a Cisco Router.=20
=09
But now I need to do that with a Cisco PIX.=20
=09
Here's the snortsam.conf file:=20
=09
accept 127.0.0.1=20
pix <PIXIP> <TELNETPASSWORD> <ENABLEPASSWORD>=20
=09
When I try to launch both snort and snortsam I see these
messages, and it seems that snortsam is applying the rules on the pix:=20
=09
Checking for existing state file: Present. Reading State=20
Starting to listen for Snort alerts.=20
Accepted connection from 127.0.0.1=20
Accepted connection from 127.0.0.1=20
Adding sensor 127.0.0.1 to list.=20
Blocking host <IP> completely for 7200 seconds=20
Accepted connection from 127.0.0.1=20
Blocking host <IP> completely for 7200 seconds=20
Accepted connection from 127.0.0.1=20
Blocking host <IP> completely for 7200 seconds=20
=09
and so on...=20
=09
By the way if I look at the Pix configuration there are no rules
applied.=20
I know that the PIX Plugin use the shun command to block IP, and
if i try it manually on the Pix it works.=20
=09
I've tried to disable telnet for the Snort/Snortsam server on
the Pix to see if Snortsam works anyway. If I do that SnortSam says it
can't connect to Pix.=20
So it seems that SnortSam "works"....=20
=09
Thanks for help=20
=09
=09
Davide De Boni
=09
Email: d.deboni@edexter.it
=09
e.Dexter S.P.A.
C.so Risorgimento 5
28823 Ghiffa (VB)
ITALIA
Tel +39.0323.407733
Fax +39.0323.53558


------_=_NextPart_001_01C43763.EED7DFC8
Content-Type: text/html;
charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Message</TITLE>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2800.1400" name=3DGENERATOR></HEAD>
<BODY>
<DIV><SPAN class=3D133562414-11052004><FONT face=3DArial color=3D#0000ff =
size=3D2>The=20
shuns won't show up in the rulebase.&nbsp; Connect to the pix, get to an =
enable=20
prompt, and type 'sh shun' to see if the shuns are being applied.&nbsp; =
It=20
should show a list of the current shuns in place.</FONT></SPAN></DIV>
<DIV><SPAN class=3D133562414-11052004><FONT face=3DArial color=3D#0000ff =

size=3D2></FONT></SPAN>&nbsp;</DIV>
<DIV><SPAN class=3D133562414-11052004><!-- Converted from text/plain =
format -->
<P><FONT size=3D2>Andrew Hutchinson - Network Security<BR>Vanderbilt =
University=20
Medical Center<BR>(615) 936-2856<BR></FONT></P></SPAN></DIV>
<BLOCKQUOTE style=3D"MARGIN-RIGHT: 0px">
<DIV></DIV>
<DIV class=3DOutlookMessageHeader lang=3Den-us dir=3Dltr =
align=3Dleft><FONT=20
face=3DTahoma size=3D2>-----Original Message-----<BR><B>From:</B>=20
snort-users-admin@lists.sourceforge.net=20
[mailto:snort-users-admin@lists.sourceforge.net] <B>On Behalf Of=20
</B>d.deboni@edexter.it<BR><B>Sent:</B> Tuesday, May 11, 2004 8:45=20
AM<BR><B>To:</B> snort-users@lists.sourceforge.net<BR><B>Subject:</B>=20
[snort-users] Blocking with a PIX<BR><BR></FONT></DIV><BR><FONT=20
face=3Dsans-serif size=3D2>Hi to everyone,</FONT> <BR><BR><FONT =
face=3Dsans-serif=20
size=3D2>I've configured snort with snortsam to block attacks from the =

outside.</FONT> <BR><FONT face=3Dsans-serif size=3D2>It worked all =
perfectly when=20
I tried it on a Cisco Router.</FONT> <BR><BR><FONT face=3Dsans-serif =
size=3D2>But=20
now I need to do that with a Cisco PIX.</FONT> <BR><BR><FONT =
face=3Dsans-serif=20
size=3D2>Here's the snortsam.conf file:</FONT> <BR><BR><FONT =
face=3Dsans-serif=20
size=3D2>accept 127.0.0.1</FONT> <BR><FONT face=3Dsans-serif =
size=3D2>pix=20
&lt;PIXIP&gt; &lt;TELNETPASSWORD&gt; &lt;ENABLEPASSWORD&gt;</FONT>=20
<BR><BR><FONT face=3Dsans-serif size=3D2>When I try to launch both =
snort and=20
snortsam I see these messages, and it seems that snortsam is applying =
the=20
rules on the pix:</FONT> <BR><BR><FONT face=3Dsans-serif =
size=3D2>Checking for=20
existing state file: Present. Reading State</FONT> <BR><FONT =
face=3Dsans-serif=20
size=3D2>Starting to listen for Snort alerts.</FONT> <BR><FONT =
face=3Dsans-serif=20
size=3D2>Accepted connection from 127.0.0.1</FONT> <BR><FONT =
face=3Dsans-serif=20
size=3D2>Accepted connection from 127.0.0.1</FONT> <BR><FONT =
face=3Dsans-serif=20
size=3D2>Adding sensor 127.0.0.1 to list.</FONT> <BR><FONT =
face=3Dsans-serif=20
size=3D2>Blocking host &lt;IP&gt; completely for 7200 seconds</FONT> =
<BR><FONT=20
face=3Dsans-serif size=3D2>Accepted connection from 127.0.0.1</FONT> =
<BR><FONT=20
face=3Dsans-serif size=3D2>Blocking host &lt;IP&gt; completely for =
7200=20
seconds</FONT> <BR><FONT face=3Dsans-serif size=3D2>Accepted =
connection from=20
127.0.0.1</FONT> <BR><FONT face=3Dsans-serif size=3D2>Blocking host =
&lt;IP&gt;=20
completely for 7200 seconds</FONT> <BR><BR><FONT face=3Dsans-serif =
size=3D2>and so=20
on...</FONT> <BR><BR><FONT face=3Dsans-serif size=3D2>By the way if I =
look at the=20
Pix configuration there are no rules applied.</FONT> <BR><FONT =
face=3Dsans-serif=20
size=3D2>I know that the PIX Plugin use the shun command to block IP, =
and if i=20
try it manually on the Pix it works.</FONT> <BR><BR><FONT =
face=3Dsans-serif=20
size=3D2>I've tried to disable telnet for the Snort/Snortsam server on =
the Pix=20
to see if Snortsam works anyway. If I do that SnortSam says it can't =
connect=20
to Pix.</FONT> <BR><FONT face=3Dsans-serif size=3D2>So it seems that =
SnortSam=20
"works"....</FONT> <BR><BR><FONT face=3Dsans-serif size=3D2>Thanks for =
help</FONT>=20
<BR><BR><FONT face=3Dsans-serif size=3D2><BR>Davide De =
Boni<BR><BR>Email:=20
d.deboni@edexter.it<BR><BR>e.Dexter S.P.A.<BR>C.so Risorgimento =
5<BR>28823=20
Ghiffa (VB)<BR>ITALIA<BR>Tel +39.0323.407733<BR>Fax=20
+39.0323.53558</FONT></BLOCKQUOTE></BODY></HTML>
=00
------_=_NextPart_001_01C43763.EED7DFC8--


-------------------------------------------------------
This SF.Net email is sponsored by Sleepycat Software
Learn developer strategies Cisco, Motorola, Ericsson & Lucent use to
deliver higher performing products faster, at low TCO.
http://www.sleepycat.com/telcomwpreg...rom=osdnemail3
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 02:22 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0