[Prelude Hybrid IDS] #209: cisco-asa rules dont work when changing syslog logging levels

"Prelude Hybrid IDS" <[email protected]>
Newsgroups gmane.comp.security.ids.prelude.devel
Message-ID <[email protected]>
#209: cisco-asa rules dont work when changing syslog logging levels
--------------------------------------------+-------------------------------
 Reporter:  [email protected]  |       Owner:  yoann            
     Type:  defect                          |      Status:  new              
 Priority:  normal                          |   Milestone:  Prelude-LML 0.9.9
Component:  prelude-lml                     |     Version:  0.9              
 Severity:  normal                          |    Keywords:  cisco ruleset    
--------------------------------------------+-------------------------------
 all cisco pix/asa syslog messages begin with a prefix like this:

 {{{
 %PIX-<logging_level>-<message_number>
 }}}

 it is possible to change the logging level of alerts so that, for example,
 a message that is normally informational (level 6) will be displayed at
 the warning level (level 4).  this changes the logging_level part of the
 message prefix.  unfortunately, this causes the current cisco rules to
 stop working, because they depend on the default logging_level.  the rules
 should not care about the logging_level, as it is user-configurable on the
 pix itself (this is probably true for cisco routers and switches as well).

-- 
Ticket URL: <https://trac.prelude-ids.org/ticket/209>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://www.prelude-ids.org/mailman/listinfo/prelude-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.