Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5510 with SSM-10 ARC

Hello there,

I am configuring remote host blocking on SSM-10 within ASA to make shun on certain signatures. SSM-10 resides on the same ASA on which it should perform shun action. But unfortunately it doesn't work. ASA version ins 8.4(3) and IPS version is 7.0(7)E4.

Here is error messages I get on IPS:

  errorMessage: ErrSystemError PIX [1.1.1.1] version major and minor values were not matched  name=errUnclassified 

  errorMessage: Firewall [1.1.1.1] is unable to add a block for [2.2.2.2] due to an error.  name=errSystemError 

1.1.1.1 is ASA ip address, and 2.2.2.2 is attacker which triggered signature with shun action.

I even tried to use telnet between ASA and IPS to communicate but same result.

Everyone's tags (5)
2 REPLIES
Cisco Employee

ASA 5510 with SSM-10 ARC

It maybe helpful to provide the output for the following commands to debug this issue in more detail :

sensor# show statistics network-access

and

sensor# show event error

Run the second command preferably at the same time when SSM sends the shun message to the ASA.

thanks

Madhu

ASA 5510 with SSM-10 ARC

Do you have the SSM configured in promiscuous or inline mode?  The blocking/ARC config is only relevant for promiscuous configurations. If you have the sensor configured for inline in the service policy on the ASA, then the SSM can directly deny offending traffic.  I have seen instances of this error before when you are attempting to configure blocking for an inline sensor.

666
Views
0
Helpful
2
Replies