Fleeing from a host on the PIX 520 but alerts that are still coming to the IDS

Last week I saw allot of traffic from a particular host that triggers alerts IDS. After investigating the source, I added a statement SHUN to the pix. When I do a 'sho shun stat' of the NTC for this host is quite high (352) and rises. I still get alerts of the IDS on this particular host (Fragment IP and host sweeps). I guess if I was fleeing from an IP address, I don't receive alerts of IDS on that. Can someone explain what I am doing wrong? Thanks in advance.

Seems obvious, but can't hurt to ask - where the sniff of your sensor interface? Of course, if your sniffing interface is located outside the pix, then junk traffic will always reach the pix - it just won't be through it.

In addition, are fleeing this host for these alarms? Doing a show 'show shun' that host being blocked FOR the time you see alerts for this particular host?

Jeff

Tags: Cisco Security

Similar Questions

  • What will happen to the computers that are still using Windows XP?

    Original title: Windows XP?

    So, what will happen to the computers that are still using windows xp? Say, my computer is too old to support something newer than XP

    On April 8, 2014, support and updates for Windows XP will be more available. Don't let not your PC not protected. 
    http://Windows.Microsoft.com/en-AU/Windows/end-support-help

    You need to consider your options carefully. You can always run XP but be aware of the risks. It is always your decision what you decide to do.

    Cyber-threats for Windows XP and advice to small businesses and individual consumers

    http://blogs.technet.com/b/Security/Archive/2014/03/24/cyber-threats-to-Windows-XP-and-guidance-for-small-businesses-and-individual-consumers.aspx

  • Cache question? My Cache in Bridge is full, how do I do that the purge? Will I lose anything as my thumbnail or photo files that are still on my computer

    Cache question? My Cache in Bridge is full, how do I do that the purge? Will I lose anything as my thumbnail or photo files that are still on my computer?

    Hello

    You can purge the cache of the following option

    Preferences-> Cache-> purge all the Cache now

    You will not loose original photos to the computer. It will remove created bridge Cache of thumbnails / images.

    You can also set no.. a value of days to automatically purge older option preferences-> Cache cache.

    Please let me know if you have any additional questions.

    Kind regards

    Anil

    Adobe Bridge team

  • I cleaned the print heads, but the printed letters are still coming from pale grey.

    I have a HP Photosmart eStation all in one printer-C510a.  When I print the works are very pale.  I changed the ink cartrideges and cleaned the print heads.  Still very pale.  Any ideas what to do next?

    Hi rab27,.

    Thank you for visiting the Forums from the HP Support! I understand that when you are printing on your HP Photosmart eStation C510, the output is very pale, you attempted to clean the print heads and replace cartridges without success. In order to better assist you, what is the current operating system you use, Windows or Mac and what version?

    I assure you, you are able to make a copy. Can make you a black copy with no problems?

    Now we will make sure that you do not have the printer to print in black and white only. Please follow the steps listed below:

    1. go to your Start Menu

    2. Select devices and printers

    3. right click on your C510 and access print options

    4. click on the advanced option

    5. in the section of the characteristics of the printer, make sure that it is not set to print in grayscale

    Now, let's go and run HP print and Scan Doctor- designed by HP to offer users the features and troubleshooting problem needed to solve many common problems experienced with HP print and scan the products related to Windows computers.

    If you have changed the printing preferences, ran the PSDR HP without success, please continue here: Troubleshooting print quality problems

    I hope this helps, let me know the result.

    Thank you

  • I want to save an IMAP via POP3 account in Thunderbird, but it will not download old emails that are still on the server. How can I do this?

    I start using Thunderbird to save and purge old e-mails from an account via POP3. This account is accessible by other users using IMAP on their computers and mobile phones.

    I want to archive and purge old messages from the server using Thunderbird. But it will not download messages that apparently are marked as read on the server via IMAP.

    POP mail accounts must be configured to "leave messages on server".
    Check this box before use.

    • Tools > account settings > server for the e-mail account settings

    or

    • menu icon > Options > account settings > server for the e-mail account settings

    Select: 'leave messages on the server.

    Optional: select: "during the more than xx days" this will remove something more that select the specified number of days "until I have delete" when you delete an email it will be deleted from the server.

    Click Ok to save the settings.

    POP mail accounts are only looking at the Inbox and download everything that has not been previously downloaded regardless of whether it has been read or not. They cannot access or download from any other folder on the server.

    If you want to download the e-mail messages in other directories, you must move the emails in the Inbox to upload and it's may not be practical in your situation.

    What you can do is to synchronize your IMAP folders to a copy downloaded to your IMAP e-mail account.
    Then switch mode 'offline' to stop any additional synchronization synchronized files update.
    MozBackup tool could now be used to save the profile synchronization created mbox files that contain emails.

    You can also do the following to get a copy outside the IMAP e-mail account:
    Create the same folders in the "local folders".
    Then right click on the email and "copy to" and select local folders and the folder you need.
    Put a copy in the local files means these e-mails are also on your computer and they are not influenced by what you do in the IMAP folder.
    You need backup emails in these folders.
    See info:

    MozBackup:

    ImportExporttool:

  • Hello, I have my PC connected to my HDTV and when viewing websites on firefox, Web sites are too small to read. What can I do to solve this problem. I tried dling the add-on no. Squint, but some sites are still distorted. Thanks for your help

    My PC specs:
    Intel Core 2 Quad 2.5 GHz
    NVIDIA 9800GT video card
    600 GB of Seagate hard drive

    The TV is a Philips 720 p (not exactly what model it is)

    You can increase the chain pref layout.css.devPixelsPerPx from 1.0 to 2.0 in 0.1 steps to discover what works best.
    In Firefox 3.6 and later this pref is a string parsed in float value and allows you to adjust the dimensions of all elements more precisely.

    See http://kb.mozillazine.org/about%3Aconfig

  • How to recover missing files that are still on the hard drive. iTunes and VLC Player can still read the files.

    I had a restore of the system without success and now all my files (music, photos, documents, PDF files, vids, etc) are missing.  My itunes still recognizes the path to music and can play everything.  Same thing with VLC player and photos.   For example, if I go in VLC player and watch my playlist, I see that info a video is C:\Users\kevarendt\Desktop\Vids\... and the player will play the video.  However, I can't file my own.  He is no longer on my desk, where he was saved, but the path always displays it's there.  My drive is still in his usual capacity, so none of my files have been deleted.  I can't even to my user account.  All I see is a Public folder in C:\Users\.  What happened to my user account?  All the paths to my files have nothing to show, but it's still there but invisible.  How can I access it.  I use Vista Home Premium.

    Hello

    I suggest you to check that the same in safe mode if you work, try to perform the clean boot

    Note: After troubleshooting, be sure to set the computer to start as usual as mentioned in step 7 in the above article.

    If not work then suggest to activate the hidden files and folders and then check if it works very well.

     
  • Disappeared from the toolbar URL, and modules are not coming back.

    Hi people. Once more Firefox drives me crazy, I woke up this morning, turned on the old computer, Firefox has started, and I have no URL bar. I tried to restore it, but no luck. Been looking for the Firefox forums for a few hours, found similar questions, but... .no cigar. I have the version 36.0.4 of Firefox. Can someone please explain how he disappeared and how to get it back?

    I uninstalled FF, entirely. And re-installed. URL bar still to go. Also, I have connected to my SYNC, but my modules are not coming back.

    I would appreciate your help.

    You still have the Navigation bar visible with other buttons on the toolbar and tab bar?

    Make sure that you run not Firefox mode full screen (press F11 or Fn + F11 to toggle; Mac: Command + SHIFT + F).

    If you are in full screen view then hover over with the mouse to the top of the screen to facilitate the bar appear Navigation and tab bar.
    Click the expand (in the top right Navigation bar) to exit full screen or right-click on a space empty on a toolbar and select "exit full screen" or press the F11 key.

    Try to rename (or delete) the file xulstore.json in the Firefox profile folder.
    You can use this button to go to the Firefox profile folder currently in use:

    Start Firefox in Safe Mode to check if one of the extensions (Firefox/tools > Modules > Extensions) or if hardware acceleration is the cause of the problem.

    • Put yourself in the DEFAULT theme: Firefox/tools > Modules > appearance
    • Do NOT click on the reset button on the startup window Mode safe
  • The features of virtual machine that are not supported or disabled material...

    I get this error when I try to migrate virtual machines from one host to another.

    but some other virtual machines to migrate.

    What's wrong? I have

    and if the reason EVC mode I think that I can not migrating other virtual machines, am I right?

    1.jpg

    Jokerciitaw thanks for the reply, but I can't understand if you're right... How can I migrate some other virtual machines?

  • Configuration of the PIX 520 with two links to Internet

    Hello.

    I have a pix 520 with four interfaces ethernet firewall, in fact I am with

    just two interfaces,

    Ethernet 0 outdoors

    Ethernet 1 inside

    ethernet2 closed intf2

    ethernet3 closed intf3

    Thus, in the interface to the outside, I have access to the internet, but now I

    access to the internet and I want to configure the two, I mean,.

    a single network inside and two internet access,

    is it posible?

    the perhaps configuration.

    Ethernet 0 (access 1) outdoors

    1 Ethernet (ip 10.1.1.1) inside

    ethernet2 outside2 (access to internet 2)

    ethernet3 inside2? (ip 10.1.1.2)?

    Thanks for the help,

    You can plug it in like that, but there is no way to route traffic by default. PIX does not support this type of connections that you can only configure a default route on the pix. This link should help describe what you can do: http://www.cisco.com/warp/public/110/pixfaq.shtml#Q18

    I hope this helps.

    Kurtis Durrett

  • ACI - cannot reach hosts outside the fabric until the traffic is inititated from a host outside in a host connected to the fabric

    I have a group of the same EPG and VLAN statically mapped ports on my fabric of ACI.  One port connects to a port on a stack of 3750 x uplink.  Hosts on the fabric, I cannot ping hosts on the 3750 until I have initiated traffic from hosts on the 3750 in the fabric.  Once it done on each host of 3750, they can talk to each other.  Why is this happening?

    Thank you!

    When traffic is a failure, the destination will probably not learned as an EP in the fabric.  You can check by looking at the operational tab of the EPG.

    Once you ping the 3750, we learn the EP and traffic works from the original source.  When the BD "Equipment Proxy" mode, the destination must be learned.

    If you change the mode of the 'Flood' comic, then inundate us and learn as a normal switch.

    Joey

  • vCenter server from unit 5.5 after the migration from one host to another host

    Hello


    I had to migrate our VCenter Server Appliance VM (5.5 x) that uses the database into another ESXi host.

    Once the VM has moved successfully from one host to another, after the virtual machine restarts, I'm not able to connect to it.

    I get the following error: Client is not authenticated to the Service of the inventory of VMware - https://web-vcenter1:10443

    I searched and followed many articles KB including KB 2037952 with no luck. I refreshed the

    SSL certificates, etc. and ideas.


    Thank you

    Shiva

    Hi Ryan,

    I fixed all my issues in upgrading the VCSA to the latest version. Version 5.5.0 Build 2414847

    Other treatments VCSA had already been upgraded to this version and it worked very well.

    Thanks for help with ideas.

    PS: You were right - I log in as root and not as an administrator and this is why I did not see the SSO pages.

    -Shiva

  • Migrate the virtual machine for Exchange 2010 from one host to another

    Dear members,

    Please let know us if the migration of a virtual machine for Exchange 2010 is supported to an Esxi host to another, the Esxi version is 5.0.

    There are unique Exchange environment with the role of hub, CAS and mailbox on the same virtual server. We have a maintenance window and we think moving exchange virtual machine from one host to another, but before that I need to be sure if it's supported my MS and do not want to have problems after, because I have also gotten to know here in the forums this snapshot for Exchange 2010 is not supported by Ms.

    Please notify.

    Kind regards

    I'm not aware of any limitations with VMS Exchange migration. Anyway, you can consider running the migration during the low workload.

    André

  • How to enable the communication between the host and the virtual from Windows 7 computer

    Host: Mac OS X 10.6

    Setting of networking: NAT (also connected to the VPN work)

    VM: Windows 7

    I use my mac for my development. I have an application running with the Web Server server. I also use the hosts so that I can map the URLS of different web site with the same ip address.

    For example:

    On my Mac in/etc/hosts

    127.0.0.1 www.testsite1.com www.testsite2.com

    On my virtual from Windows machine in the hosts file

    987.78.125.125 www.testsite1.com www.testsite2.com

    When I'm at the office and using bridged connections, it works very well. However, I prefer to use NAT all the time.

    Is this possible?


    Thank you!

    I actually already answer your question but now I know the details, and by the way you have explained so much better the second time!

    When not connected to the VPN on the host computer and the guest knows the IP address of the Web server on the host (an appropriate entry in the guest hosts) then it should work but when connected to the VPN, if you are administrator does its job well, that you should not be able to connect the host to the guest for the reason mentioned previously...  Authenticated/no unapproved system (guest) cannot access an authenticated / trust system (host), while the VPN on the host computer is set up to your corporate network.

  • How to move templates of virtual machines from one host to another, if the partners host is offline

    Hi people,

    I knew that I need to convert a virtual computer model to a VM to move from one host to another, but that when the host, that the model is associated with, is offline / broken? Is it possible to make it work again on the vsphere client or only via the command-line interface of cmd and save the model with the host?

    Thanks in advance.

    Kind regards

    Bjoern

    You can try this...

    If you have another ESX host to add the data store to which the template is stored.

    After that browse the data store and go to the directory of the model. Select the model VM file and add it to the inventory and select the host on which you want to add the template... After you have added the host convert VM...

    Thank you

    Please indicate if useful...

Maybe you are looking for

  • need to adapt the string values when writing to a text file

    Hello I have problem by lining up all of the data in wise coloumn. the output is (see attachment). I'm trying to solve this problem, but seems to be difficult. help please...

  • Original HP replacement parts

    Hello Sir, I would like to know if I could buy hood origin of HP Pavilion g6 2102tx online.

  • W520 and C:/root

    Just got my new Lenovo w520 a few days ago. Does anyone know what C:/root and C:/root/wpfdot.exe are for? I wasn't sure based on a quick google search of "wpfdot.exe". Thank you

  • remove the external hard disk image

    There are on my external hard drive that I would use in a project I am working on photos.  I can find information on how to put photos on an external hard drive, but nothing about deleting the photos in my external hard drive to place and use somewhe

  • Why won't my computer allow me to create new folders on my usb key?

    It wasn't a problem before. He began to arrive only about 2 weeks ago. Basically, whenever I add a new folder on my USB, my laptop I cannot add a few. He said nothing. The main problem is that when I click on the button to the right (on the mouse), t