Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

RE: Updating Enterasys Dragon NIDS signature...

Subject: RE: Updating Enterasys Dragon NIDS signature...
Date: Tue, 9 Aug 2005 05:57:45 -0400
Hello Jean-Pierre. 

I know you can manually download the entire Dragon IDS signature set in
.tgz format from the Enterasys support site. Do you have a requirement
to perform this update automatically from the DPM?  If they don't have
Internet access then it seems you'll have to sneaker-net the updated
signature set in each time. Do you have an account on their support site
and if so, do you know where to look for the manual signature download?
If not GTAC can point you to this information (provided you're talking
with someone in the Dragon group). 

Also, if your DPM and Forensics Console are on different server
machines, then you'll have to put the updated signatures and the
dragon.conf (I think that's the right file) on both machines.  Otherwise
when the new signatures are pushed to the sensors and start firing, they
show up in the Unknown group. 

Hope this helps. 

Scott Hazel
Unisys Managed Security Services
Scott.hazel@unisys.com 

-----Original Message-----
From: Jean-Pierre Denis [mailto:jp@webglobe.ca] 
Sent: Saturday, August 06, 2005 8:13 PM
To: focus-ids@securityfocus.com
Subject: Updating Enterasys Dragon NIDS signature...

Hi everyone,


  I have a bunch of Dragon NIDS to update but they don't have internet
  connection to do so. Since it's a closed network the update screw up
  everytime because enterasys designed it to access their site.

  Does someone have this type of experience with Dragon appliance?

  Enterasys is not very helpful and I don't know where to start.


Merci,
Jean-Pierre Denis
 (LPIC1 - LPIC2)
WebGlobe Solutions TI
email: jp@webglobe.ca
tel.: (819) 246-0WWW (0999)
www:   http://www.webglobe.ca


-----------------------------------------
 WebMail Powered by WebGlobe. 
 http://www.webglobe.ca     


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from
CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it 
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
to learn more.
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>