cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
220
Views
0
Helpful
1
Replies

Intrusion reporting

u080570
Level 1
Level 1

I have "inherited" our PIX515 firewall and have been requested to provide an intrusion report. I am going through all the documentation, but I figured someone here would be able to point me in the right direction alot faster! Im using Cisco Secure Policy Manager v.2.3.2....what's the best way to create an intrusion report?

Thanks!

Mark

1 Reply 1

s-doyle
Level 3
Level 3

I'm not very sure as to what you mean by the term 'intrusion report'. However, here is some information that might help. IDS is available only for PIX 6.0 and later. The signatures are contained in syslog messages 400000 through 400051 (aka Cisco Secure IDS signature messages). A comprehensive list of PIX System Log Messages is available at http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_system_message_guide_chapter09186a008008d2b2.html#xtocid262426.Another documents that might help is 'Logging Network Activity and Generating Notifications - Cisco Policy Manager' http://www.cisco.com/en/US/products/sw/secursw/ps2133/products_user_guide_chapter09186a00800e95ab.html