X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fpix_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fpix_rules.xml;h=ab83089d36bafd46d2fd8a2a35c61143b660ec7b;hp=0000000000000000000000000000000000000000;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b diff --git a/debian/ossec-hids/var/ossec/rules/pix_rules.xml b/debian/ossec-hids/var/ossec/rules/pix_rules.xml new file mode 100644 index 0000000..ab83089 --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/pix_rules.xml @@ -0,0 +1,237 @@ + + + + + + + + + pix + Grouping of PIX rules + + + + 4300 + ^1- + PIX alert message. + + + + 4300 + ^2- + PIX critical message. + + + + 4300 + ^3- + PIX error message. + + + + 4300 + ^4- + PIX warning message. + + + + 4300 + ^5-|^6- + PIX notification/informational message. + + + + 4300 + ^7- + PIX debug message. + + + + 4314 + ^6-605004 + Failed login attempt at the PIX firewall. + authentication_failed, + + + + 4314 + ^5-502103 + Privilege changed in the PIX firewall. + + + + 4314 + ^6-605005 + Successful login to the PIX firewall. + authentication_success, + + + + 4314 + ^6-308001 + Password mismatch while running 'enable' + on the PIX. + authentication_failed, + + + + 4313 + ^4-405001 + ARP collision detected by the PIX. + + + + 4313 + ^4-401004 + Attempt to connect from a blocked (shunned) IP. + access_denied, + + + + 4313 + ^4-710004 + Connection limit exceeded. + + + + 4310 + ^1-106021|^1-106022 + Attack in progress detected by the PIX. + + + + 4311 + ^2-106012|^2-106017|^2-106020 + Attack in progress detected by the PIX. + + + + 4313 + ^4-4000 + Attack in progress detected by the PIX. + + + + + 4330, 4331, 4332 + Attack in progress detected by the PIX. + ids, + + + + 4314 + ^6-113005 + AAA (VPN) authentication failed. + authentication_failed, + + + + 4314 + ^6-113004 + AAA (VPN) authentication successful. + authentication_success, + + + + 4314 + ^6-113006 + AAA (VPN) user locked out. + authentication_failed, + + + + 4312 + ^3-201008 + The PIX is disallowing new connections. + service_availability, + + + + 4310 + ^1-105005|^1-105009|^1-105043 + Failed|Lost Failover + Firewall failover pair communication problem. + service_availability, + + + + 4314 + ^5-111003 + Firewall configuration deleted. + config_changed, + + + + 4314 + ^5-111005|^5-111004|^5-111002|^5-111007 + Firewall configuration changed. + config_changed, + + + + 4314 + ^5-111008|^7-111009 + Firewall command executed (for accounting only). + + + + 4314 + ^5-502101|^5-502102 + User created or modified on the Firewall. + adduser,account_changed, + + + + 4310 + Multiple PIX alert messages. + + + + 4311 + Multiple PIX critical messages. + + + + 4312 + Multiple PIX error messages. + system_error, + + + + 4313 + Multiple PIX warning messages. + + + + 4333 + + Multiple attack in progress messages. + + + + 4334 + Multiple AAA (VPN) authentication failures. + authentication_failures, + + + + +