11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 11: Intrusion Detection and PreventionReturn valueThe return value of fbidsmate is zero if the command executedsuccessfully; otherwise it is non-zero. This valueshould be checked upon return if calling fbidsmate from ashell script or through some other interface.ExamplesIn the following examples, the IP address of the <strong>Firebox</strong> is10.0.0.1 with a configuration passphrase of “secure1”.Example 1The IDS detects a port scan from 209.54.94.99 andasks the <strong>Firebox</strong> to block that site:fbidsmate 10.0.0.1 secure1 add_hostile209.54.94.99The 209.54.94.99 site appears on the auto-blockedsites list and remains there for the duration set inPolicy Manager. In addition, the following messageappears in the log file:Temporarily blocking host 209.54.94.99Example 2The IDS adds a message to the <strong>Firebox</strong>’s logstream:fbidsmate 10.0.0.1 secure1 add_log_message 3"IDS system temp. blocked 209.54.94.99"With the IDS running on host 10.0.0.2, thefollowing message appears in the <strong>Firebox</strong> log file:msg from 10.0.0.2: IDS system temp. blocked209.54.94.99Example 3Because you are running your IDS applicationoutside the firewall perimeter, you decide toencrypt the configuration passphrase used in yourIDS scripts. Note that even with encryption, youshould lock down the IDS host as tightly as196 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!