Integrating Intrusion Detection
User Guide
195
Using the fbidsmate command-line utility
The fbidsmate utility works from the command line.
Although you can execute the commands directly against
the Firebox, the tool is used most frequently in the context
of an IDS application script. The command syntax is:
fbidsmate
firebox_address
[
rwpassphrase
| -f
rwpassphrase_file
] [add_hostile
hostile_address
] |
[add_log_message
priority(0-7)
"
message
"]
fbidsmate
import_passphrase
rwpassphrase
rwpassphrase_filename
add_hostile
This command adds a site to the Auto-Blocked Site
list, with the duration set by the administrator in
Policy Manager’s
Blocked Sites
dialog box. It
effectively extends your control of the Auto-Block
mechanism inside the Firebox.
add_log_message
This command causes a message to be added to the
log stream emitted by the Firebox. Because the
priority is used by the Firebox to construct syslog
messages, its range is the standard syslog
0=Emergency to 7=Debug. There is no limit on
message length; the message is automatically
broken into multiple messages if necessary.
import_passphrase
You can store the Firebox configuration passphrase
in encrypted form instead of putting it in clear text
in your IDS scripts. This command stores the
passphrase in the designated file using 3DES
encryption. Rather than using the configuration
passphrase, use the file name in your scripts. If you
are managing multiple Fireboxes, you need one
passphrase file per Firebox.
Summary of Contents for Firebox X10E
Page 1: ...WatchGuard Firebox System User Guide WatchGuard Firebox System ...
Page 12: ...xii WatchGuard Firebox System ...
Page 44: ...Chapter 2 Service and Support 22 WatchGuard Firebox System ...
Page 61: ...Cabling the Firebox User Guide 39 ...
Page 68: ...Chapter 3 Getting Started 46 WatchGuard Firebox System ...
Page 78: ...Chapter 4 Firebox Basics 56 WatchGuard Firebox System ...
Page 156: ...Chapter 8 Configuring Filtered Services 134 WatchGuard Firebox System ...
Page 182: ...Chapter 9 Configuring Proxied Services 160 WatchGuard Firebox System ...
Page 220: ...Chapter 11 Intrusion Detection and Prevention 198 WatchGuard Firebox System ...
Page 242: ...Chapter 12 Setting Up Logging and Notification 220 WatchGuard Firebox System ...
Page 256: ...Chapter 13 Reviewing and Working with Log Files 234 WatchGuard Firebox System ...
Page 274: ...Chapter 14 Generating Reports of Network Activity 252 WatchGuard Firebox System ...