11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Integrating Intrusion DetectionUsing the fbidsmate command-line utilityThe fbidsmate utility works from the command line.Although you can execute the commands directly againstthe <strong>Firebox</strong>, the tool is used most frequently in the contextof an IDS application script. The command syntax is:fbidsmate firebox_address [rwpassphrase | -frwpassphrase_file] [add_hostile hostile_address] |[add_log_message priority(0-7) "message"]fbidsmate import_passphrase rwpassphraserwpassphrase_filenameadd_hostileThis command adds a site to the Auto-Blocked Sitelist, with the duration set by the administrator inPolicy Manager’s Blocked Sites dialog box. Iteffectively extends your control of the Auto-Blockmechanism inside the <strong>Firebox</strong>.add_log_messageThis command causes a message to be added to thelog stream emitted by the <strong>Firebox</strong>. Because thepriority is used by the <strong>Firebox</strong> to construct syslogmessages, its range is the standard syslog0=Emergency to 7=Debug. There is no limit onmessage length; the message is automaticallybroken into multiple messages if necessary.import_passphraseYou can store the <strong>Firebox</strong> configuration passphrasein encrypted form instead of putting it in clear textin your IDS scripts. This command stores thepassphrase in the designated file using 3DESencryption. Rather than using the configurationpassphrase, use the file name in your scripts. If youare managing multiple <strong>Firebox</strong>es, you need onepassphrase file per <strong>Firebox</strong>.<strong>User</strong> <strong>Guide</strong> 195

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!