USG60W and flex 200 - V4.62 Insufficient privilege when disabling tcp-portscan from command line

danyedinak
Posts: 51
Ally Member




I have twenty routers to manage, so logging into the web GUI is a non-starter. I need command line functionality.
Just prior to PCI-DSS scans I need to temporarily disable the tcp-port scan to prevent it from being tripped by the scan (although, having whitelisted IPs would be better) and then re-enable after the scan is complete. From the command line (SSH from putty in windows or command line in Debian):
enable
configure terminal
idp anomaly ADP_PROFILE no scan-detection tcp-portscan activate
% Insufficient privilege
Same username CAN make the change via the web gui, which, again, does not help me solve this problem.
Just prior to PCI-DSS scans I need to temporarily disable the tcp-port scan to prevent it from being tripped by the scan (although, having whitelisted IPs would be better) and then re-enable after the scan is complete. From the command line (SSH from putty in windows or command line in Debian):
enable
configure terminal
idp anomaly ADP_PROFILE no scan-detection tcp-portscan activate
% Insufficient privilege
Same username CAN make the change via the web gui, which, again, does not help me solve this problem.
0
Comments
-
Update - entering as a subcommand solves the problem. However, this is still a bug, or the help (when hitting tab) should be changed to remove the option there. There's also a secondary issue with the spelling of anomaly (it's spelled as anomlay).
Router(config)# idp anomaly ADP_PROFILE
Router(config-idp-anomlay-profile-ADP_PROFILE)# no scan-detection tcp-portscan activate
0 -
Hi @danyedinak,
Thank you for your feedback.
For first issue, please refer to CLI guide. It's normal behavior. That commands need to execute in the sub-command mode.
For the typo error, we will fix this in the upcoming releases. Please kindly wait for upcoming releases.
Best regards1
Categories
- All Categories
- 431 Beta Program
- 2.6K Nebula
- 165 Nebula Ideas
- 112 Nebula Status and Incidents
- 6K Security
- 365 USG FLEX H Series
- 292 Security Ideas
- 1.5K Switch
- 78 Switch Ideas
- 1.2K Wireless
- 42 Wireless Ideas
- 6.6K Consumer Product
- 262 Service & License
- 407 News and Release
- 87 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.9K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 83 Security Highlight