Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Search results for query: *

  1. DavidHalko

    PIX IDS Alerts via SNMP or SysLog

    OK - so the current number is 53 signatures... The URL you provided was pretty close... http://www.cisco.com/en/US/products/sw/iosswrel/ps1831/products_command_summary_chapter09186a00800880a6.html This is a great little article on the Cisco IOS! The problem is, these commands only work with...
  2. DavidHalko

    PIX IDS Alerts via SNMP or SysLog

    Hey - >I've found out so far is 515/525s come with 50 IDS signatures as default. ... >logging on >logging trap (debugging comes as default...) >logging facility (from 17 or 23 or 22 or 21 or 20) >logging server w.x.y.z OK - well, this I have had set up. > but is supposed to be in the PIX...
  3. DavidHalko

    PIX IDS Alerts via SNMP or SysLog

    I have some 515's and 525's. The IOS's are varied. The PIX is supposed to detect/repell for dozens of intrusions according to dozens of signitures. I remember reading a list of IDS codes, at one time, when my previous security expert showed me a printout. Ever so often, during an IOS...
  4. DavidHalko

    PIX IDS Alerts via SNMP or SysLog

    Thanks a lot... It has been like "pulling teeth" trying to figure out how to configure the PIX to send the IDS messages through a standards based mechanism, as well as determine what message is an ID message! EMS Architect
  5. DavidHalko

    PIX IDS Alerts via SNMP or SysLog

    I am familiar with sending traps and syslog messages from a PIX to an snmp manager or a syslog daemon. The intrusion detection messages (which are detected via signatures) are at question. I have not been able to find these things, anywhere in the Cisco Documentation or how to even determine...
  6. DavidHalko

    Monitoring servers with NNM

    Try this... If you are running HO OV NNM under UNIX (Solaris, for example), there are easy ways to handle this. The 3 files of interest are: "/etc/networks", "/etc/netmasks", and "/etc/hosts". If you know the network number for each location ( 10.10.1.x...
  7. DavidHalko

    SNMP or SYSLOG status of PIX VPN Tunnel

    Hey - Yes - logging to a UNIX syslog server already. You really never want to log at a debugging level of 7. That is way too much trash to read through... ... establishing a connection from x to y ... tearing down a connection from x to y and so forth. There is just so much stuff coming...
  8. DavidHalko

    SNMP or SYSLOG status of PIX VPN Tunnel

    Perhaps Cisco's web page... http://www.cisco.com/ http://www.cisco.com/univercd/home/home.htm http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/index.htm This does not seem like that difficult of a request! :-) EMS Architect
  9. DavidHalko

    SNMP or SYSLOG status of PIX VPN Tunnel

    The "pollable" snmp MIBS are pretty weak. I have not found any interesting "SNMP traps" either. Heck - I can't even find any easy command line'ers to tell what IPSEC tunnels are built and operating correctly! It seems like management was the LAST thing they thought about...
  10. DavidHalko

    SNMP or SYSLOG status of PIX VPN Tunnel

    > Does PIX write something to the syslog when tunnelling fails? I do not know! I am also in need of such information using the VPN technology in standard Cisco IOS routers... I have a couple of those too! EMS Architect
  11. DavidHalko

    PIX IDS Alerts via SNMP or SysLog

    How would one receive IDS alerts from a PIX via SNMP Traps or Syslog Events? What is the message encoding for the IDS events in the traps or syslog events? I have a PIX and if someone tries a "ping of death" or some other known intrusion, I would like to be able to log it and...
  12. DavidHalko

    SNMP or SYSLOG status of PIX VPN Tunnel

    Is there a way to determine the status of a PIX VPN tunnel either through SNMP Traps, SNMP Gets or Syslog Alerts? When a PIX to PIX tunnel is established and it fails, I would like to get an indication of when the tunnel fails. I would also like to be able to query the device to find out...
  13. DavidHalko

    Web view

    The HP Web Interface is not very robust. If you absolutely HAVE to have a Web Interface 1) which HAS to be stable (operations group) or 2) which HAS to be exported through a firewall for an external customer view I would recommend purchasing an add-on product which would be stable called...
  14. DavidHalko

    Too Long Syncronizing

    Try to set up the OV NNM box without DNS and see the results. Due to the unpredictability of DNS while being fed off of another platform that is not under your control, I would recommend that you do not run with DNS at all. I have found that a script which populates an /etc/hosts table and...
  15. DavidHalko

    Forwarding all events from HP OV NNM as traps

    PawelW - Can you post the code you used to split the trap stream? (perhaps a solaris binary? :-) ) EMS Architect
  16. DavidHalko

    snmpCollect and netmon crashing

    > I am running NNM 6.31 on Solaris 8. Recently, I have been doing a large amount of discovering of remote segments. For the last 2 days every time I bring up ovw snmpCollect and netmon crash with in 15 – 20 min. - - - - - Oh yea... questions... 1 do you happen to be running 280R's? 2 will...
  17. DavidHalko

    HP openview 6.31

    If you are using HP OpenView on a Sun Solaris system, this is fairly straight forward. 1 Connect a null modem serial cable from the UNIX platform to the other platform. 2 Configure the serial ports to talk using the same baud and parity settings (Solaris offers a GUI called admintool...
  18. DavidHalko

    octet ??

    > It also depends on if you are using half or full duplex on the NIC... Let's help out here... Serial Links (Frame Relay, Point-to-Point, ATM, etc.) - These are usually Full Duplex LAN Links (1 MBit, 10 MBit) - These are usually Half Duplex LAN Links (100 MBit, 1 GBit, 10 GBig) - These are...
  19. DavidHalko

    Topology & Configuration check - Intervals

    The topology and configuration check intervals are handled by "netmon", if I remember correctly. This should be explained in the UNIX man page on netmon. From your root prompt, you can view the file via: # more $OV_CONF/polling EMS Architect
  20. DavidHalko

    HI, How do I integrate HP with Remedy?

    Remedy used to ship an interface to HP OV NNM that was FREE for the longest time. As soon as Remedy managed to become a monopoly, they discontinued shipping the interface. > ARSPerl to allow OV to interface with Remedy pretty well... Can you get Perl to sit on the trap stream in OV NNM...

Part and Inventory Search

Back
Top