-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Oct 4, 2010, at 8:32 PM, dan (ddp) wrote:
> You probably won't be able to install it on the system. Export the
> logs via syslog to monitor the logs. If there's a way to ssh into the
> system and run a command to see the configuration (like "show config"
> or something) you can use the agentless configuration to monitor
> system changes.

I'd also recommend looking into using something like RANCID [1] for this...  
RANCID is designed specifically for this task, including keeping past revisions 
so you can see changes over time. OSSEC still plays a role here in that you can 
use it to monitor the syslog traffic from the ASA and alert on problems, take 
action when it detects attacks, etc.

[1] http://www.shrubbery.net/rancid

- ---------------------------
Jason 'XenoPhage' Frisvold
[email protected]
- ---------------------------
"Any sufficiently advanced magic is indistinguishable from technology."
- - Niven's Inverse of Clarke's Third Law



-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.14 (Darwin)

iEYEARECAAYFAkyqh80ACgkQ8CjzPZyTUTSigwCfVPo2zmVfDTBVl/eBzgwFonX+
J3EAnRYS9s9bFKCupjmdNWF5i02VtW7X
=Jnum
-----END PGP SIGNATURE-----

Reply via email to