cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
519
Views
0
Helpful
6
Replies

Does Pix 6.22 include IDS

mitchell_kohn
Level 1
Level 1

Hi, I noticed that there is a monitoring piece in my PDM that includes IDS. But when I looked at the histories, there wasn't anything there. Is there something special to make it work, or is it a separate piece of hardware ?

Thanks

6 Replies 6

devam
Level 1
Level 1

PIX IOS has IDS with Limitied features. These features can identify certain attack signatures. Based on the configuration the malicious packets can be blocked etc.

Thank you.

Murthy.

bikmann
Level 1
Level 1

My understanding is that IDS is already active by default. As Murthy suggested, it is an option to buy for more Intrusion Detection Signatures. By default I believe it comes with some standard 50 to 55 signatures.

The IDS features of the Pix are VERY limited and are not enabled by default. They are enabled per interface using the [ip audit] commands.

They are very basic and cannot be upgraded as an option. New Pix code releases are the only method to "upgrade" the IDS signatures. For example, pix 6.3.1 code included a few new signatures above 6.2.2.

It seems like I can not put in anything under policy to interface mappings via PDM or cli. What am I missing ?

Thanks.

These commands would create to IP audit polices that both "alarm" only and applies them to the outside interface:

ip audit name outside-ids info action alarm

ip audit name outside-ids2 attack action alarm

ip audit interface outside outside-ids2

Thanks, I will try it.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card