Daniel,

Thanks *very* much for the quick response.  I tried that as well, and
got a timeout error.

I know that when I puTTY over to my ASA, it asks me to validate the
SSH fingerprint.

So either way, I'm having a problem....

Thoughts welcome

TIA

Dave Rosenblatt
davidr521 (at) gmail.com

On Apr 16, 6:23 pm, Daniel Cid <[email protected]> wrote:
> Hi Dave,
>
> You need to provide a user name in the host field. It should be in the
> format u...@host. Plus, it should
> match what you gave for the register_host.
>
> If you look at our examples, we always use u...@host:
>
> <host>[email protected]</host>
>
> That should solve your problem.
>
> Thanks,
>
> --
> Daniel B. Cid
> dcid ( at ) ossec.net
>
> On Thu, Apr 16, 2009 at 6:20 PM, Dave <[email protected]> wrote:
> > All,
>
> > I may be a bit of a chowderhead here (it's been known to happen), but I've
> > now spent two days solid trying to wrap my head around getting OSSEC
> > connected to my Cisco ASA.
>
> > A few items of note:
> > * I _don't_ want to change where I'm syslogging
> > * I want to do this agentless
>
> > I have:
> > * Run register_host.sh (# /var/ossec/agentless/register_host.sh add
> > [email protected] mypass1).  I'm _assuming_ from everything I'm reading that the
> > syntax is <add asausern...@ip_address_of_asa logonpassword enablepassword>
> > * Modified /var/ossec/etc/ossec.conf as follows:
> >   <agentless>
> >     <!-- Assuming this will work... [DAR] 04-16-09 -->
> >     <type>ssh_pixconfig_diff</type>
> >     <frequency>60</frequency>
> >     <host>my_ip_address_here</host>
> >     <state>periodic_diff</state>
> >   </agentless>
> > I'm assuming that I _don't_ have to put the asausername in the <host>
> > clause?  But hey, I have no idea.
> > * Restarted OSSEC by running /var/ossec/bin/ossec-control restart
>
> > Here's what I end up with in ossec.log:
> > --------------------------------------------------------------------------- 
> > ---------------------------------------------------------------------------
> > 2009/04/16 16:25:35 ossec-agentlessd: ERROR: ssh_pixconfig_diff:
> > my_ip_address_here: Password for 'my_ip_address_here' not found.
> > 2009/04/16 16:26:36 ossec-agentlessd: ERROR: ssh_pixconfig_diff:
> > my_ip_address_here: Password for 'my_ip_address_here' not found.
> > 2009/04/16 16:27:37 ossec-agentlessd: ERROR: ssh_pixconfig_diff:
> > my_ip_address_here: Password for my_ip_address_here' not found.
> > 2009/04/16 16:28:38 ossec-agentlessd: ERROR: Too many failures for
> > 'ssh_pixconfig_diff'. Ignoring it.
> > --------------------------------------------------------------------------- 
> > ---------------------------------------------------------------------------
> > Of course, I replace 'my_ip_address_here' with the valid IP address.
>
> > I can ping the box from my OSSEC box.
>
> > What I'm after is what's on the bottom ofhttp://www.ossec.net/dcid/?p=158:
> > --------------------------------------------------------------------------- 
> > ---------------------------------------------------------------------------
> > For the PIX:
> > OSSEC HIDS Notification.
> > 2008 Dec 01 15:48:03
> > Received From: (ssh_pixconfig_diff) [email protected]>agentless
> > Rule: 555 fired (level 7) -> “Integrity checksum for agentless device
> > changed.”
> > Portion of the log(s):
> > ossec: agentless: Change detected:
> > 48c48
> > < fixup protocol ftp 21
> > —
> >> no fixup protocol ftp 21
> > 100c100
> > < ssh timeout 30
> > —
> >> ssh timeout 50
> > More changes..
> > –END OF NOTIFICATION
> > --------------------------------------------------------------------------- 
> > ---------------------------------------------------------------------------
>
> > I fear it's a problem with an SSH fingerprint, but I haven't the foggiest
> > idea how to resolve it.
>
> > I know the email works, because OSSEC sends me a friendly "Hey there!" email
> > whenever I do a restart:
>
> > --------------------------------------------------------------------------- 
> > ---------------------------------------------------------------------------
> > OSSEC HIDS Notification.
> > 2009 Apr 16 15:41:55
> > Received From: OSSIM->ossec-monitord
> > Rule: 502 fired (level 3) -> "Ossec server started."
> > Portion of the log(s):
> > ossec: Ossec started.
>
> >  --END OF NOTIFICATION
> > --------------------------------------------------------------------------- 
> > ---------------------------------------------------------------------------
>
> > I _really_ need to replace Tr*pwire, and I know OSSEC can do it.  Just not
> > sure where to go from here.
>
> > Any help would be *greatly* appreciated.

Reply via email to