Fleeing does not work with pix 6.1 (4)

I use IDS sensor version 3,0000 S36 and pix version 6.1 (4), and I'm doing fleeing on pix using telnet. But I am facing the problem in the errors.managed:

17/12/2002 13:32:06UTC E Read error [operation now in progress] fd [3]

17/12/2002 13:33:11UTC Comm E timeout for [pix_IP]. No recovery will be given at this time.

17/12/2002 13:33:57UTC Comm E timeout for [pix_IP]. No recovery will be given at this time.

Notes:

-the configuration file managed.conf is correct

-I can telnet manually (from the command line) of the sensor for the pix, so there is no problem of communication.

-I know that this problem is reported for pix 6.2 (1), it applies also to 6.1 (4)?

-in the file managed.conf is the conf: "NetDevice [pix_IP] PIX [telnet_pass] [enable_pass].

but when I run the command "nrgetbulk 10003 hostid orgid 1 NetDevice" on the sensor, I get:

"Cisco [telnet_pass] [enable_pass] [pix_IP].

Anyone have a solution beside the answer "use ssh?

You can get a little more detailed diagnostic information

by running the command "nrget 10003 hostid orgid 1 diagnosis.

This will tell you the status of all net devices used to fleeing.

You can also determine whether the CSCdx55215 bug occurs

on your sensor:

The sensor, telnet to the PIX command line. If you

See the banner "User access authentication", then the

bug will occur and you will need to get the nr.managed

Engineering code for CSCdx55215.

Here is a link that requires a CCO, the version code beta account:

http://www.Cisco.com/cgi-bin/tablebuild.pl/NIDs

If you download the file, please send me an email

([email protected] / * /) and I'll give installation instructions.

I'm sure you see this bug because one of

the side effects, is that the PIX is misleading as router

(i.e. Cisco instead of PIX).

Tags: Cisco Security

Similar Questions

Maybe you are looking for