<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS IDS question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520352#M161406</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_command_reference_chapter09186a008017cf19.html#wp1072958" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_command_reference_chapter09186a008017cf19.html#wp1072958&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 May 2006 12:49:23 GMT</pubDate>
    <dc:creator>irisrios</dc:creator>
    <dc:date>2006-05-26T12:49:23Z</dc:date>
    <item>
      <title>IOS IDS question</title>
      <link>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520351#M161405</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit protected [ip address - ip address]&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;according to cco it defines a protected address space for IDS, this is from cisco.&lt;/P&gt;&lt;P&gt;An attack signature detects attacks attempted into the protected network, such as denial-of-service attempts or the execution of illegal commands during an FTP session. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_c/ftrafwl/scfids.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fsecur_c/ftrafwl/scfids.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;i have tested IDS today with ICMP flooding, i got alarms for ICMP attack SIG .2050 even without configuring this command.&lt;/P&gt;&lt;P&gt;does anybody know, what exactly this command does?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Louis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520351#M161405</guid>
      <dc:creator>lkrucker</dc:creator>
      <dc:date>2019-03-10T10:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IDS question</title>
      <link>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520352#M161406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_command_reference_chapter09186a008017cf19.html#wp1072958" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_command_reference_chapter09186a008017cf19.html#wp1072958&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 May 2006 12:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520352#M161406</guid>
      <dc:creator>irisrios</dc:creator>
      <dc:date>2006-05-26T12:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IDS question</title>
      <link>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520353#M161407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks but unfortunately its still not clear for me. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If no addresses are defined as protected, then all addresses are considered outside the protected network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;may i should phrase my question a little bit different&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i am not configuring that command, what kind of attack would not be detected? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 May 2006 06:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520353#M161407</guid>
      <dc:creator>lkrucker</dc:creator>
      <dc:date>2006-05-29T06:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IDS question</title>
      <link>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520354#M161408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume the "flagged alert" in the command reference means a relict of the Postoffice protocol.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 10:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520354#M161408</guid>
      <dc:creator>herbert.aichhorn</dc:creator>
      <dc:date>2007-06-27T10:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IDS question</title>
      <link>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520355#M161409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You must be using a very old version of IOS in which the IDS feature is using 'ip audit...' command to configure, in these version of IOS, the IDS feature has a fixed number of hardcoded signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IOS IDS/IPS feature has evolved quick a bit, starting 12.3(8)T, it starts support dynamic signatures and is a true inline ips sysstem. Recently, from 12.4(11)T, it supports 5.x signature format which enables ips to support signatures with encrypted parameter values and more functions (But this is not backward compatible w/ previous version).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information, please check Cisco.com at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6634/products_ios_protocol_group_home.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6634/products_ios_protocol_group_home.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also please check the white paper and Q&amp;amp;A section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2007 16:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ids-question/m-p/520355#M161409</guid>
      <dc:creator>ymzhang</dc:creator>
      <dc:date>2007-06-27T16:40:11Z</dc:date>
    </item>
  </channel>
</rss>

