Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX IDS Signatures

Hello,

I would like to know if there is any description of the IDS signatures on the PIX.

I have looked at the dokumentation for PIX but there you have descriptions for all messages except the IDS.

3 REPLIES

Re: PIX IDS Signatures

IDS is available only for PIX 6.0 and later. The signatures are contained in syslog messages 400000 through 400051, referred to as the Cisco Secure IDS signature messages.

See link for details on each signature:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_61/syslog/pixemsgs.htm#xtocid6

New Member

Re: PIX IDS Signatures

Hello, Steve!

Yes I have read that document. But the IDS-messages have no "explanation" and no "action" as the other messages have. So my question is were I can find information where the are an explanation and a recommended action.

Best Regards

Robert Maras

Re: PIX IDS Signatures

I can't find a link on the web site, but they are the same as those in the IDS, ie the NSDB (network security database). In the cisco press book, Chapter 10 IDSPM, it lists all IDS signatures. So you can look in the book or in CSPM in the NSDB. For example a UDP bomb will be explained and will list a recommended action, deny or log, and you can have the PIX do the same.

Hope it helps.

Steve

227
Views
0
Helpful
3
Replies