Good way to configure "never block addresses?

ID 4210 2.0000 S47

PIX 515 v6.2 (2)

What is the proper way to 'never block' a whole network in IDM?

The network behind the firewall with a private IP address range (10.10.10.1 - 254, for example) it's NAT would have on the external interface of the PIX.

When an of these IPs gets shunned, I can't make a 'no shun' using the address private IP and the shun is deleted. Then... I guess I can enter the private IP address to 'never block '.

But... I did this and the IP get sometimes shunned.

Do I need to use the global public address pool these get NAT'd to?

Can I enter the following in the IDM to 'never block' across the network? :

10.10.10.0

255.255.255.0

Tony

The addresses that you use in the never order block on the sensor must correspond to the location where the sensor is deployed.

If the sensor is monitoring on your private network and generates alarms with private IP addresses then use IP addresses private when you configure never block.

If the sensor is followed on the external network and generates alarms with the global ips then use the global ips when configuring never block.

Then look at your alarms and see what address is reported in the alarm (private or global). This is the address or network you want to configure as never to block.

The sensor doesn't know what private ip addresses are mapped to addresses what global ip. If a block on a private address never has no effect on whether or not the sensor will block a global address.

The Pix knows the mapping, it's why the shun no order on the Pix will remove it. The Pix knows the mapping is not the case of the probe.

Beware that if the sensor is turned off and reboot of the sensor re - runs the command to shun for all addresses that it deems should be avoided (even those that you have run the command 'not shun' for the pix). Is not a good idea to manually run the command 'not shun' on the Pix when the IDS sensor actively manages the list of shun.

Instead, go to IDM on the sensor and delete (delete) the shun:

Step 11 in these instructions: http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids10/idmiev/swchap5.htm#987105

The probe won't do then the "no shun" automatically for you.

To configure the networks never block:

http://www.Cisco.com/univercd/CC/TD/doc/product/iaabu/csids/csids10/idmiev/swchap3.htm#32488

(Remember to use the network that corresponds to the period of investigation (private or global) don't appear in the alarm)

Or use these CLI commands:

Configure the terminal

NetworkAccess service

General

never shun networks ip address 1.0.0.0 netmask 255.0.0.0

Replace 1.0.0.0 and 255.0.0.0 with either private or global network according to what is reported in the alarm.

Tags: Cisco Security

Similar Questions

  • Firefox has detectedthe server redirects the request to an address in a way that will never end

    Firefox has detected that the server redirects the request for this address in a way that will never end it is verbatim it's never happened before

    We have the same problem. Ours is a little out of the ordinary that we have a web application that displays pages based on a configuration of a database for the "namesake" page is created over and over again that our users make their way through our investigations.

    Is there a method on the side Server things, what can be done to stop this error from appearing? We tried some experiments as alternating in the title of the page, redirect between two different pages but FF still think it is to see the same page over and over again.

    We would love to be able to support FF for our clients and their customers (those who take our surveys) and it is a crucial issue at the moment for some of our customers worldwide.

    Any help would be greatly appreciated.

    Thank you
    ~ Dave Carr
    800, Inc. service.
    [email protected]

  • Firefox has detected that the server redirects the request for this address in a way that will never end. I followed your instructions and nothing works. This just started happening today.

    I was watching www.ustream.tv/decoraheagles for months. I started using Firefox about a month ago. Earlier today, when I tried connecting to the site, I received the message "Firefox has detected that the server redirects the request for this address in a way that will never end."
    I went on your site and follow the instructions. This Web site was not in the blocked sites. He told me how to add it, and I did.
    She still refuses to open this site.
    Internet Explorer WILL open this site.

    Clear the cache and cookies from sites that cause problems.

    "Clear the Cache":

    • Tools > Options > advanced > network > storage (Cache) offline: 'clear now '.

    'Delete Cookies' sites causing problems:

    • Tools > Options > privacy > Cookies: "show the Cookies".
  • Firefox has detected that the server redirects the request for this address in a way that will never end.

    This week (01/10/12) I registered on youtube and now I can't log back in here or in my gmail account. I tried every fix-it/single remedy offered the FF forum but nothing works.

    Any other work, all the sites that I frequent load fine, is youtube doing something on purpose for FF users? I can get the page youtube videos and see, but I can't log on, every time I click the sign in button, I get:

    "The page is not redirecting properly".

    Firefox has detected that the server is redirecting the request for this address in a way that will never complete.
    

    This problem can sometimes be caused by disabling or refusing to accept cookies. »

    I hate to be a conspiracy theorist, I can connect to youtube without problem on IE, but I hate this browser. I use windows 7 and 15 FF. Can someone find it?

    Looks like it's a firefox issue, because that never happened on IE, Safari or Opera on me.
    You think not that a simple patch can solve this problem. I have to delete individual cookies every day.

  • message from Firefox: "page isn't redirecting properly" Firefox has detected that the server redirects the request for this address in a way that will never end. * Why this mess

    "The page isn't redirecting properly?

    i receive this warning on a daily basis. it seems to occur whenever i open a message  in gmail or try to send a message. anybody have a clue about this? thanks!
    

    Firefox has detected that the server redirects the request for this address in a way that will never end.

       *   This problem can sometimes be caused by disabling or refusing to accept
             cookies.
    

    See http://kb.mozillazine.org/The_page_is_not_redirecting_properly

  • How to configure anti-spam to block addresses email not valid

    We receive a lot of spam that (fortunately screenshots of anti-spam) are directed to a non-existent user in our Organization. Is there a way to configure anti-spam to reject completely?

    I have a TZ205 with comprehensive services. firmware update

    Antispam on the firewall is no not no matter what filtering of recipients.

    Antispam on the firewall uses a Proxy connection and depends on the mail server to reject invalid recipient.

    The complete Email Security product rejects invalid recipients (Protection of DHA)

    The Hosted Email Security currently does not DHA Protection but it is added at a later date.

  • OsCustomizationSpec and OSCustomizationNicMapping they are a good way to set up the new virtual machine for the model

    I build a script to generate auto magicly VM when I have import information from a csv file. I have the latest PowerCli, I am trying to build servers r2 Sever 2012 model.  I tried several OsCustomizationSpec (OCS) of in the hope of getting something to work, but I had no luck so far.  In VCenter, it shows that it applies the OCS, but is not apear to have an impact on the server.  I have disabled UAC since the last time that I tried it so maybe that will make a difference.  I am under ESXi 5.1 update 2, just to try to give all the necessary information.  Ideally, I'd like Sysprep, the value of intellectual property, change the computer name and join the server to the domain.  That's all! lol I have the book "VMware vSphere PowerCLI Reffernece, automating vSphere Administration, I walked through step by step.  The new version of PowerCli seems not have the x 86 limitation as earlier versions of PowerCli.  I tried so many different things, I'm not sure what to put in place as a starting point.

    # Save the object credentials with permission to join the domain.
    $DomainCredentials = get-Credential "domain\testername."
    # Clone our Spec by adding the domain information.
    $Spec = get-OSCustomizationSpec "Windows Server 2012 R2"
    $Spec += get-OSCustomizationNicMapping - Spec $Spec
    #$Spec | Select *.

    # Get our VM
    # Change network settings
    Get - VM BigServername | Get-NetworkAdapter | Together-NetworkAdapter - NetworkName nic - 172.16.25 - VLAN225 - connected: $true '
    -Confirm: $false | out-null
    # Close the comments to make change.
    Stop-VMGuest - VM $VM - confirm: $false | out-null
    # Wait while feedback stops
    While ($vm. ExtensionData.Runtime.PowerState - not "poweredOff")
    {
    Start-Sleep - seconds 1
    $vm. ExtensionData.UpdateViewData ('Runtime.PowerState')
    }
    # Apply Spec customization to apply the new network settings
    Get - VM "BigServername" |
    Set-VM - OSCustomizationSpec "R2 Windows Server 2012" - confirm: $false |
    Start-VM

    I can rebuild the model, or something else, we must do this work.

    OR - is simply not the best way to configure the VM?  If not, what Sysprep?

    Good news, but first, I would really like to know where the log files are on which server to the OsCustomization process.

    I decided to reverse engineer and create a CSOS within vCeneter and once I got to work, I kept creating new CSO via PowerCli until I could get that to work, create a new virtual machine.  Once I got this to work, I have tryied to apply on a cloned vm, with no parameters. I got it works too.  I tried to go back to my original image, but I couldn't get this to work.  Something's wrong with this picture.  He wrath that the problem was related to the permissions on the local client.

    New OSCustomizationSpec - OrgName company OSType - Windows - ChangeSid-Server "vcenter.dom.com" - name PowerCliOnly4 - persistent administrator-Type FullName - AdminPassword! password123 - zone "Eastern (USA and Canada)" AutoLogonCount - 3 - domain dom dadmin - DomainUsername - DomainPassword! password123 NamingScheme - vm-Description "PowerCli Use only" - confirm: $false

    Get-OSCustomizationNicMapping - OSCustomizationSpec PowerCliOnly4 | Game-OSCustomizationNicMapping - Position 1 - IpMode UseStaticIP - IpAddress 10.10.10.98 - 255.255.255.0 - DefaultGateway 10.10.10.1 Dns subnet - mask "10.10.10.10","10.10.10.11" "-confirm: $false

    This seems to be very picky.  Because the area is one of the parameters, you cannot put it in the DomainUsername, no dom\dadmin. The part that I really want to know how to get more, is what happens if your vm has a different local administrator as the administrator account.  It turns out that FullName - is not the account that it to connect locally with tires. When I created the vCenter Medtronic Chondroitin, I put 'me' in the name and information of the Organization and that's what was settled in the FullName property:

    Name: PowerCliOnlyM
    Type: persistent
    ServerId: /VIServer = dom\[email protected]: 443.
    Server: vcenter.dom.com
    LastUpdate: 24/09/2014 13:33:19
    DomainAdminUsername: dadmin NO dom/dadmin here!
    DomainUsername: dadmin
    Description: PowerCli use only, done manually in vCenter.
    AutoLogonCount: 3
    ChangeSid: true
    DeleteAccounts: false
    DnsServer:
    DnsSuffix:
    Domain: vsi
    Full name: me
    GuiRunOnce:
    NamingPrefix:
    NamingScheme: Vm
    OrgName: CompanyTU
    OSType: Windows
    ProductKey:
    Time zone: (USA and Canada)
    Working Group:
    LicenseMode: NotSpecified
    LicenseMaxConnections:
    EncryptionKey: {-126, 3, 48, 108...}
    ExtensionData: VMware.Vim.CustomizationSpecItem
    ID: PowerCliOnlyM
    UID: /VIServer = vsi\[email protected]: 443/OSCustomizationSpec = PowerCliOnlyM /.
    Client: VMware.VimAutomation.ViCore.Impl.V1.VimClient
    AdminPassword: w
    DomainAdminPassword: N
    DomainPassword: N

    DNS: {10.10.10.10, 10.10.10.11}
    Wins                  :
    SpecId: PowerCliOnlyM
    Spec: PowerCliOnlyM
    SpecType: persistent
    NetworkAdapterMac:
    Position: 1
    IPMode: UseStaticIP
    IP address: 10.10.10.98
    Subnet mask: 255.255.255.0
    DefaultGateway: 10.10.10.1
    AlternateGateway:
    VCApplicationArgument:
    ID: /VIServer = dom\[email protected]: 443/OSCustomizationNicMapping = OSCustomizationNicMappingImpl-PowerCliOnlyM-persistent-1.
    UID: /VIServer = dom\[email protected]: 443/OSCustomizationNicMapping = OSCustomizationNicMappingImpl-PowerCliOnlyM-persistent-1.
    ExtensionData: VMware.Vim.CustomizationAdapterMapping
    Client: VMware.VimAutomation.ViCore.Impl.V1.VimClient
    Version: 1

    I think that it is good to know that the virtual machine reboot 4 or 5 times as it goes through this process.  It breaks is you try and do something for the virtual machine that interrupt the process.  I don't know that I'll think more questions in a second.

    In addition, it cost he had some problems with the put between quotation marks, single or double around the password, but I did not check this again, I just know that once I took them, he began to work.  I ran on other issues while testing as I was using a single IP address, so if I do not disable the test VM, the following would not work because of the conflct network, maybe I shouldn't admit that... lol

  • What is a good way to use the queues for the model of consumers/producers?

    Hi all

    I am following the model of consumers/producers to use the queue to synchronize the following process: the producer is a loop to produce a number N, I will put each number generated in a table and after each 5 numbers generated, I put the table in the queue and pass it on to the consumer. I have to wait the use by consumers of the data and it will then remove the item from queue so that producers will have the chance to produce another 5 numbers. As I put the maximum size of the queue one, I expect that the producer and the consumer turns to produce / consume all five numbers and the opportunity to another. Here is my code

    When the checkbox is false, the code will be

    For the first 5 numbers, product will generate every thing right and put it in the table, and it's going to pass the array to the quere so that the consumer will have the chance to loop through the table. I except the procude loop will continue only when the queue is available (i.e. all items are deleted), but it seems that once the consumer starts the loop loop of the product will continue (if the indicator x + 1 and x 2 will be changed to numbers). But this isn't what I want, I know there must be something wrong, but I can't say it is.

    dragondriver wrote:

    As you say in 1, sequency structure to enforce the order of execution, that's why I put it here, in this example, the simple question, I replace the complete code with increase in the number, in the real case, the first markers + 1 and + 2 must be performed in this order.

    Mikeporter says:
    1. get rid of all the structures of the sequence. None of them are nothing but apply a work order which would have been the same without them.

    So even if you delete the sequence structure, there will be a fixed & defined order and it is because LabVIEW follows the MODEL of FLOW OF DATA.

    Data flow model (more precisely in the context of LabVIEW): a block diagram node runs when it receives the required inputs. When a node is running, it produces output data and transmits data to the next node in the path of the data stream. The flow of data on the nodes determines the order of execution of the VIs and functions on the block diagram (click here for reference).

    Now in your code, just remove the sequence structure will not make you order will be going to stay the same, but you need to do some very minor changes (as thread of the error in loop, before that he go to the node "Élément Dequeue").

    Come to the main point: it's a good way to use the queue for the consumer/pmodel that?
    The model you are using (and qualifying as consumer/pmodel) is much too deviated from the original consumer/pmodel which model.

    dragondriver wrote:

    For the second, Yes, it's my fault for delete, though. I'm actually the example of model of producer/consumer design pattern, but I do not pay attention to the while loop in the part of the consumer.

    While loops (two producers & consumers) are the essential part of this architecture and cannot be deleted. You can start your code using standard model.

  • DHCP server does not start - the storage control block address is invalid.

    I use a trial version of the Pro Workstation 12.1.1 on Windows 10. I seem to have a strange problem where the DHCP service does not start.

    I tried to go into the virtual network editor and then restore the default settings, which had no effect.

    The event viewer displays the following text:

    CreateFile Version ioctl(): VMnet8 (327680 393216): the operation completed successfully.

    / The storage control block address is invalid

    Checked the service and it runs under a local, verified system account permissions on the config dhcp / rental file in c:\programdata\vmware\ and both have system configured to full control. I tried to run the vmnetdhcp.exe in a command prompt to we hope to get additional information, but cannot be executed directly. I can't figure out how to get out of documented logging dhcp server in order to track down what could be the culprit.

    I tried to uninstall workstation, restart, reinstall, restart both unsuccessfully. I had version 9 workstation that was installed previously, in which the trial upgrade.

    Any suggestion would be appreciated.

    Figured it out.

    It appears during the workstation installation 9, he placed vmnetdhcp and vmnetnat in c:\windows\syswow64 folder. Pro 12 workstation puts these files in the default directory (C:\Program Files (x 86) \VMware\VMware workstation). The service was always pointing to the old location even SysWow64 after an uninstall and reinstall.

    I replaced the files SysWow64 folder workstation and services started right up.

    Checked the work by selecting NAT and gets an IP address from the host machine.

  • vSphere 5.5 using the uplink of LBT group that does not have a good way

    We use LBT since our recent deployment, which is new for us.  Everything seemed fine and dandy, until recently the VMs began dropping their connectivity to what looked like at random times.  The first fix out the door had to disconnect and reconnect the vNIC for each virtual computer.  Sometimes, it took a few tries before it worked.  We discovered that LBT moved VMS to the other group of uplink, which was a physical affair.  Unfortunately, someone didn't configure the port correctly on the remote switch, so while link came, he could not access the VLAN correct.  My question is, why the LBT would move virtual machines to an uplink group which did not have a good way?  He seeks only a physical link?  Looks like this problem waiting to happen.  Or, more likely, we have something misconfigured.  Any help would be wonderful, I don't like the idea to return to etherchannel or LACP with IP hash with blades chassis.  Thank you!

    My question is, why the LBT would move virtual machines to an uplink group which did not have a good way?

    Is that a "good path" can mean many different things in different circumstances of different points of view, if it's out of reach for LBT. It will be only on the physics of the status of the link. There is beacon probing too which can detect switch upstream outages but it can be used only with at least 3 vmnic uplinks and it has a few disadvantages, see:

    http://virtechgeek.com/2013/05/06/beacon-probing-vSphere-network-policy/

    http://thomaslowblog.blogspot.de/2011/10/vswitch-network-failover-detection.html

    You can use the dvSwitch health check feature to make sure that all the natachasery of all the hosts connected to a dvSwitch can access the same VLAN. It will not prevent LBT to move virtual machines, but it will at least raise an alarm if a bear cannot access a VIRTUAL LAN. Take a look at this article:

    http://wahlnetwork.com/2012/08/27/new-5-1-distributed-switch-features-part-1-network-health-check/

  • Is there a good way to do it?

    Is there a good way to write messages of errors in PL/SQL? For example:

    IF < variable > IS NULL THEN

    dbms_output.put_line ("' error message");

    END IF;

    OR

    IF < variable > IS NULL THEN

    RAISE < exception >;

    END IF;

    What is the most correct? Or maybe the two are quite right?

    Thank you.

    Hello

    Dbms_output is a good way of packing to write messages for debugging PL/SQL code.  It is not very good for anything else.  It is particularly inappropriate for the error messages, since the output can easily be missed, if it is never displayed at all.

    The second way you posted (STIMULUS) is good.  Create user-defined exceptions and RAISE them explicitly.

  • Good way to start with learning the concepts of 11g

    Hello

    I have a work experience on the BEA weblogic server 8.1 sp4 on which I have worked for about 2 years now. My current mission requires work to Installation / development and deployment on the server of Fusion middleware 11g. Could some body if you please suggest me a good way to start with learning the concepts of 11g.

    I understand that all the documentation is available in the Oracle forum, but I want to know where to go.

    My essential tasks in the assignment would be
    1. installation (OSB on top of WLS).
    2 development/configuration on OSB.
    3 deployment and administrative tasks.

    Kind regards
    Angelique

    Some former OSB tutorials are mentioned here: Oracle OSB - tutorial for using Eclipse plugin development

    The development of OSB guide (which shows how to use Eclipse) can be found here: http://download.oracle.com/docs/cd/E17904_01/doc.1111/e15866/toc.htm

    For now (to my knowledge), Eclipse is used for the development of OSB. Note that JDeveloper is used for development with the Oracle SOA Suite (for example Oracle BPEL).

  • Where to configure the SCAN address?

    Hello

    I'm in the middle of the installation of the cluster of grid infrastructure for Oracle 11 g 2 RAC on AIX 6.1

    I had defined the public IPs, IPs private and interconnections in the files DNS and hosts. I do not use GNS because we use static IP, no DHCP address.

    during installation, I will ask you the address IP SCAN, I prepared and resolved by the DNS, but I don't know where the configuration

    SCAN IP address is not the ping requests but can be lookedup and I get the answer that he

    When I put it, in the switch in a Rack or will I choose different installation method.

    Kindly advice

    Kind regards
    C.

    whatever Rajesh mentioned URL. I think it's the perfect way to set up.

    For the time being you can tent to configure only a single IP SCAN address in the file/etc/hosts in all nodes of the Cluster and try to move forward.

    That very sure, it won't ping until the Configuration of the grid is not complete.

    Sumit-

  • We can add money on an iphone to get the new, a good way would it cost?

    We can add money on an iphone to get the new, a good way would it cost?

    You must speak to your support for example provider (at & t, Verizon, etc.) about adding money to pay your device if not already eligible for an upgrade. Hope this helps, good luck to you.

  • When I click on bookmark it says no site configured at this address, but I know that the address is operational on the internet explore

    My Bookmark allows you to work for www.kitco.com now I juct get a white screen that says no site configured at this address. When I go on internet explore and click on Favorites, it is still there. What gives with firefox?

    Have you tried to type the address in the address bar instead of using a bookmark?

    Reload Web pages and ignore the cache to refresh potentially stale or corrupt.

    • Hold SHIFT and click reload.
    • Press 'Ctrl + F5' or 'Ctrl + Shift + R' (Windows, Linux)
    • Press 'Command + shift + R' (MAC)

    You can delete all data stored in Firefox with a specific area through "Forget this Site" from the context menu of the history entry (see the history or the history sidebar) or via the subject: permissions page.

    Using "Forget this Site" will delete all data stored in Firefox in this area as bookmarks, cookies, words of past, cache, history, and exceptions, so be careful and if you have a password or other data from this area you don't want to lose so take note of these passwords and bookmarks.

    You can't recover from which "forget" unless you have a backup of the affected files.

    It has no lasting effect, so if come back you on such a 'forgotten' site, then the data of this Web site will be saved once more.

Maybe you are looking for