Chapter 11: Intrusion Detection and Prevention
196
WatchGuard Firebox System
Return value
The return value of fbidsmate is zero if the command exe-
cuted successfully; otherwise it is non-zero. This value
should be checked upon return if calling fbidsmate from a
shell script or through some other interface.
Examples
In the following examples, the IP address of the Firebox is
10.0.0.1 with a configuration passphrase of “secure1”.
Example 1
The IDS detects a port scan from 209.54.94.99 and
asks the Firebox to block that site:
fbidsmate 10.0.0.1 secure1 add_hostile
209.54.94.99
The 209.54.94.99 site appears on the auto-blocked
sites list and remains there for the duration set in
Policy Manager. In addition, the following message
appears in the log file:
Temporarily blocking host 209.54.94.99
Example 2
The IDS adds a message to the Firebox’s log
stream:
fbidsmate 10.0.0.1 secure1 add_log_message 3
"IDS system temp. blocked 209.54.94.99"
With the IDS running on host 10.0.0.2, the
following message appears in the Firebox log file:
msg from 10.0.0.2: IDS system temp. blocked
209.54.94.99
Example 3
Because you are running your IDS application
outside the firewall perimeter, you decide to
encrypt the configuration passphrase used in your
IDS scripts. Note that even with encryption, you
should lock down the IDS host as tightly as
Содержание Firebox X10E
Страница 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Страница 12: ...xii WatchGuard Firebox System ...
Страница 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Страница 61: ...Cabling the Firebox User Guide 39 ...
Страница 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Страница 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Страница 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Страница 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Страница 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Страница 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Страница 255: ...Working with Log Files User Guide 233 appear until the remote office Firebox has been properly configured ...
Страница 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Страница 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...