[Prelude Hybrid IDS] #209: cisco-asa rules dont work when changing syslog logging levels
"Prelude Hybrid IDS" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#209: cisco-asa rules dont work when changing syslog logging levels --------------------------------------------+------------------------------- Reporter: [email protected] | Owner: yoann Type: defect | Status: new Priority: normal | Milestone: Prelude-LML 0.9.9 Component: prelude-lml | Version: 0.9 Severity: normal | Keywords: cisco ruleset --------------------------------------------+------------------------------- all cisco pix/asa syslog messages begin with a prefix like this: {{{ %PIX-<logging_level>-<message_number> }}} it is possible to change the logging level of alerts so that, for example, a message that is normally informational (level 6) will be displayed at the warning level (level 4). this changes the logging_level part of the message prefix. unfortunately, this causes the current cisco rules to stop working, because they depend on the default logging_level. the rules should not care about the logging_level, as it is user-configurable on the pix itself (this is probably true for cisco routers and switches as well). -- Ticket URL: <https://trac.prelude-ids.org/ticket/209> Prelude Hybrid IDS <http://www.prelude-ids.org> The Prelude Hybrid Intrusion Detection System suite _______________________________________________ Prelude-devel site list [email protected] http://www.prelude-ids.org/mailman/listinfo/prelude-devel