Daniel, Thanks *very* much for the quick response. I tried that as well, and got a timeout error.
I know that when I puTTY over to my ASA, it asks me to validate the SSH fingerprint. So either way, I'm having a problem.... Thoughts welcome TIA Dave Rosenblatt davidr521 (at) gmail.com On Apr 16, 6:23 pm, Daniel Cid <[email protected]> wrote: > Hi Dave, > > You need to provide a user name in the host field. It should be in the > format u...@host. Plus, it should > match what you gave for the register_host. > > If you look at our examples, we always use u...@host: > > <host>[email protected]</host> > > That should solve your problem. > > Thanks, > > -- > Daniel B. Cid > dcid ( at ) ossec.net > > On Thu, Apr 16, 2009 at 6:20 PM, Dave <[email protected]> wrote: > > All, > > > I may be a bit of a chowderhead here (it's been known to happen), but I've > > now spent two days solid trying to wrap my head around getting OSSEC > > connected to my Cisco ASA. > > > A few items of note: > > * I _don't_ want to change where I'm syslogging > > * I want to do this agentless > > > I have: > > * Run register_host.sh (# /var/ossec/agentless/register_host.sh add > > [email protected] mypass1). I'm _assuming_ from everything I'm reading that the > > syntax is <add asausern...@ip_address_of_asa logonpassword enablepassword> > > * Modified /var/ossec/etc/ossec.conf as follows: > > <agentless> > > <!-- Assuming this will work... [DAR] 04-16-09 --> > > <type>ssh_pixconfig_diff</type> > > <frequency>60</frequency> > > <host>my_ip_address_here</host> > > <state>periodic_diff</state> > > </agentless> > > I'm assuming that I _don't_ have to put the asausername in the <host> > > clause? But hey, I have no idea. > > * Restarted OSSEC by running /var/ossec/bin/ossec-control restart > > > Here's what I end up with in ossec.log: > > --------------------------------------------------------------------------- > > --------------------------------------------------------------------------- > > 2009/04/16 16:25:35 ossec-agentlessd: ERROR: ssh_pixconfig_diff: > > my_ip_address_here: Password for 'my_ip_address_here' not found. > > 2009/04/16 16:26:36 ossec-agentlessd: ERROR: ssh_pixconfig_diff: > > my_ip_address_here: Password for 'my_ip_address_here' not found. > > 2009/04/16 16:27:37 ossec-agentlessd: ERROR: ssh_pixconfig_diff: > > my_ip_address_here: Password for my_ip_address_here' not found. > > 2009/04/16 16:28:38 ossec-agentlessd: ERROR: Too many failures for > > 'ssh_pixconfig_diff'. Ignoring it. > > --------------------------------------------------------------------------- > > --------------------------------------------------------------------------- > > Of course, I replace 'my_ip_address_here' with the valid IP address. > > > I can ping the box from my OSSEC box. > > > What I'm after is what's on the bottom ofhttp://www.ossec.net/dcid/?p=158: > > --------------------------------------------------------------------------- > > --------------------------------------------------------------------------- > > For the PIX: > > OSSEC HIDS Notification. > > 2008 Dec 01 15:48:03 > > Received From: (ssh_pixconfig_diff) [email protected]>agentless > > Rule: 555 fired (level 7) -> “Integrity checksum for agentless device > > changed.” > > Portion of the log(s): > > ossec: agentless: Change detected: > > 48c48 > > < fixup protocol ftp 21 > > — > >> no fixup protocol ftp 21 > > 100c100 > > < ssh timeout 30 > > — > >> ssh timeout 50 > > More changes.. > > –END OF NOTIFICATION > > --------------------------------------------------------------------------- > > --------------------------------------------------------------------------- > > > I fear it's a problem with an SSH fingerprint, but I haven't the foggiest > > idea how to resolve it. > > > I know the email works, because OSSEC sends me a friendly "Hey there!" email > > whenever I do a restart: > > > --------------------------------------------------------------------------- > > --------------------------------------------------------------------------- > > OSSEC HIDS Notification. > > 2009 Apr 16 15:41:55 > > Received From: OSSIM->ossec-monitord > > Rule: 502 fired (level 3) -> "Ossec server started." > > Portion of the log(s): > > ossec: Ossec started. > > > --END OF NOTIFICATION > > --------------------------------------------------------------------------- > > --------------------------------------------------------------------------- > > > I _really_ need to replace Tr*pwire, and I know OSSEC can do it. Just not > > sure where to go from here. > > > Any help would be *greatly* appreciated.
