<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Test IOS IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497769#M100244</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try running a port scan on a network behind the router using something like &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nmap -sT -T Insane "network here"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should trigger an alert so you can test it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jul 2005 12:15:27 GMT</pubDate>
    <dc:creator>vasthorvak</dc:creator>
    <dc:date>2005-07-26T12:15:27Z</dc:date>
    <item>
      <title>Test IOS IPS</title>
      <link>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497768#M100234</link>
      <description>&lt;P&gt;How do you test a IOS IPS setup on a routers external interface checking inbound data is &lt;/P&gt;&lt;P&gt;working.&lt;/P&gt;&lt;P&gt;I have set it to notify via syslog (ip ips notify log) and i know the syslog &lt;/P&gt;&lt;P&gt;is working as an ACL is also set to log to syslog and this is showing &lt;/P&gt;&lt;P&gt;results on the syslog server.&lt;/P&gt;&lt;P&gt;I have tried sending (what i'm told is a ping of death) to the routers &lt;/P&gt;&lt;P&gt;external interface (ping -l 65500 ipaddress) but this shows on the syslog &lt;/P&gt;&lt;P&gt;server as being denied by the ACL but dosen't trigger a signature in the &lt;/P&gt;&lt;P&gt;IPS.&lt;/P&gt;&lt;P&gt;Is there a way of testing it from a windows platform? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497768#M100234</guid>
      <dc:creator>mike.f</dc:creator>
      <dc:date>2019-03-10T09:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Test IOS IPS</title>
      <link>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497769#M100244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try running a port scan on a network behind the router using something like &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nmap -sT -T Insane "network here"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should trigger an alert so you can test it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2005 12:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497769#M100244</guid>
      <dc:creator>vasthorvak</dc:creator>
      <dc:date>2005-07-26T12:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Test IOS IPS</title>
      <link>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497770#M100248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Generate the required traffic using the NMAP application &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can get the alert Messages from the router itself , Please make use of the SDEE messages which will give the Complete info of the alerts generated , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg :: ip ips sdee alerts&lt;/P&gt;&lt;P&gt;      ip ips sdee events &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure the sdee is enabled on the router &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2005 12:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-ios-ips/m-p/497770#M100248</guid>
      <dc:creator>bramsamy</dc:creator>
      <dc:date>2005-07-26T12:40:47Z</dc:date>
    </item>
  </channel>
</rss>

