cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
346
Views
0
Helpful
2
Replies

IDS error in the pkgadd sensor installation

ldiaz
Level 1
Level 1

I have a CISCO IDS-4235 (solaris 5.8) .

info :

I copy the /mnt/cdrom/products/agentsolaris to a local /etc/ciscohids

the files are admin , entercept.pkg , i execute the pkgadd like :

/usr/sbin/pkgadd -a /etc/ciscohids/admin -

d /etc/ciscohids/entercept.pkg

The following packages are available:

1 encpt Entercept agent

(sparc) 336

Select package(s) you wish to process (or 'all' to process

all packages). (default: all) [?,??,q]:

Processing package instance <encpt> from

</etc/ciscohids/entercept.pkg>

Entercept agent

(sparc) 336

Entercept

Processing package instance <encpt> from

</etc/ciscohids/entercept.pkg>

Please enter path for the Entercept agent directory: /etc/ciscoIDS

Please enter the IP address of the Entercept Console: x.x.x.x

Please wait for the testing of the host ...

Please enter the port number of Entercept server (default: 5000) :

Please specify the entercept agent type to be installed:

Solaris Server press 1

Solaris Web Server press 2

(default: 1) : 1

Please enter the agent name (default: myids):

Agent name is myids

The selected base directory </etc/ciscoIDS/entercept> must exist

before installation is attempted.

Do you want this directory created now [y,n,?,q] y

Using </etc/ciscoIDS/entercept> as the package base directory.

## Processing package information.

## Processing system information.

## Verifying disk space requirements.

## Checking for conflicts with packages already installed.

## Checking for setuid/setgid programs.

This package contains scripts which will be executed with super-user

permission during the process of installing this package.

Do you want to continue with the installation of <encpt> [y,n,?] y

Installing Entercept agent as <encpt>

## Installing part 1 of 1.

/etc/ciscoIDS/entercept/Params.db

/etc/ciscoIDS/entercept/ShieldGen.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/ShieldGen.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/ShieldGen.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/UnixAgent.rul

/etc/ciscoIDS/entercept/UnixAgent.scn

/etc/ciscoIDS/entercept/UnixApache.rmv

/etc/ciscoIDS/entercept/UnixApache.rul

/etc/ciscoIDS/entercept/UnixApache.scn

/etc/ciscoIDS/entercept/UnixApachehttp.rul

/etc/ciscoIDS/entercept/UnixIPlanet.rmv

/etc/ciscoIDS/entercept/UnixIPlanet.rul

/etc/ciscoIDS/entercept/UnixIPlanet.scn

/etc/ciscoIDS/entercept/UnixIPlanethttp.rul

/etc/ciscoIDS/entercept/agent.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/agent.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/agent.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/apacheEngine.so.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/apacheEngine.so.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/apacheEngine.so.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/configure.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/configure.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/configure.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/ePEngine.so.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/ePEngine.so.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/ePEngine.so.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/ePStub.so.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/ePStub.so.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/ePStub.so.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/encpt.conf

/etc/ciscoIDS/entercept/encpt.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/encpt.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/encpt.sun4u.SunOS.5.7_64

/etc/ciscoIDS/entercept/encpt.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/encpt.sun4u.SunOS.5.8_64

/etc/ciscoIDS/entercept/exceptions.db

/etc/ciscoIDS/entercept/general.rul

/etc/ciscoIDS/entercept/levels.db

/etc/ciscoIDS/entercept/libhlmed.so

/etc/ciscoIDS/entercept/mod_apacheStub.so.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/mod_apacheStub.so.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/mod_apacheStub.so.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/mod_cfginfo.so.sun4u.SunOS.5.6

/etc/ciscoIDS/entercept/mod_cfginfo.so.sun4u.SunOS.5.7

/etc/ciscoIDS/entercept/mod_cfginfo.so.sun4u.SunOS.5.8

/etc/ciscoIDS/entercept/newagent.scr

/etc/ciscoIDS/entercept/policies.db

/etc/ciscoIDS/entercept/sm

[ verifying class <none> ]

## Executing postinstall script.

It may take few minutes. Please wait ...

Install error, /etc/ciscoIDS/entercept/encpt.i86pc.SunOS.5.8 does not

exist.

pkgadd: ERROR: postinstall script did not complete successfully

Installation of <encpt> failed.

2 Replies 2

pgolding
Level 1
Level 1

why are you installing HIDS on an IDS sensor? the IDS sensor has hardened solaris already and should not require further protection.

chstone
Level 1
Level 1

As has already been suggested, the installation of HIDS on a Cisco IDS sensor is not only supported, but not required. The version of Solaris that is running on the sensor is not the full version distributed by Sun. This version has been modifed and had many service removed and features disabled. There is no reason to install any Host IDS to the sensors.

Thanks.

Chris