cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1228
Views
0
Helpful
2
Replies

ASA 5510 with SSM-10 ARC

l77l88l99l
Level 1
Level 1

Hello there,

I am configuring remote host blocking on SSM-10 within ASA to make shun on certain signatures. SSM-10 resides on the same ASA on which it should perform shun action. But unfortunately it doesn't work. ASA version ins 8.4(3) and IPS version is 7.0(7)E4.

Here is error messages I get on IPS:

  errorMessage: ErrSystemError PIX [1.1.1.1] version major and minor values were not matched  name=errUnclassified 

  errorMessage: Firewall [1.1.1.1] is unable to add a block for [2.2.2.2] due to an error.  name=errSystemError 

1.1.1.1 is ASA ip address, and 2.2.2.2 is attacker which triggered signature with shun action.

I even tried to use telnet between ASA and IPS to communicate but same result.

2 Replies 2

mkodali
Cisco Employee
Cisco Employee

It maybe helpful to provide the output for the following commands to debug this issue in more detail :

sensor# show statistics network-access

and

sensor# show event error

Run the second command preferably at the same time when SSM sends the shun message to the ASA.

thanks

Madhu

Todd Pula
Level 7
Level 7

Do you have the SSM configured in promiscuous or inline mode?  The blocking/ARC config is only relevant for promiscuous configurations. If you have the sensor configured for inline in the service policy on the ASA, then the SSM can directly deny offending traffic.  I have seen instances of this error before when you are attempting to configure blocking for an inline sensor.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: