cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1057
Views
0
Helpful
1
Replies

Configure PIX 501 for IDS

joel-metz
Level 1
Level 1

I have a PIX 501 with a broadband connection to the outside and a home office LAN on the inside. What would be a solid IDS policy to activate and what interfaces should it be applied to? Will there be any other necessary steps to activate IDS?

1 Accepted Solution

Accepted Solutions

gfullage
Cisco Employee
Cisco Employee

IDS on the PIX itself is very limited, it only checks for 59 signatures listed here (http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/gl.htm#xtocid9 under the Supported IDS signatures section). The signatures themselves are the fairly basic ones.

If you do want to enable this, then for the attack signatures I'd set the action to alarm/drop/reset, which is default anyway.

You'll also want to set up logging to a syslog server and monitor it for any 4000nn syslog messages, cause these will be IDS events.

View solution in original post

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

IDS on the PIX itself is very limited, it only checks for 59 signatures listed here (http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_62/cmdref/gl.htm#xtocid9 under the Supported IDS signatures section). The signatures themselves are the fairly basic ones.

If you do want to enable this, then for the attack signatures I'd set the action to alarm/drop/reset, which is default anyway.

You'll also want to set up logging to a syslog server and monitor it for any 4000nn syslog messages, cause these will be IDS events.

Review Cisco Networking products for a $25 gift card