<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Snort IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820418#M42570</link>
    <description>&lt;PRE&gt;nmap scan&lt;/PRE&gt;
&lt;P&gt;what command you scan ? what what is the IP address rance you scanned ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2019 21:01:54 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2019-03-15T21:01:54Z</dc:date>
    <item>
      <title>Snort IPS</title>
      <link>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820253#M42569</link>
      <description>&lt;P&gt;All&lt;/P&gt;
&lt;P&gt;I have following configuration:&lt;/P&gt;
&lt;PRE&gt;interface VirtualPortGroup0
  ip address 192.168.200.101 255.255.255.0
Interface VirtualPortGroup1
  description Data interface
  ip address 192.168.0.1 255.255.255.0 &lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;PRE&gt;virtual-service myips
  vnic gateway VirtualPortGroup0
    guest ip address 192.168.200.100 255.255.255.0
  vnic gateway VirtualPortGroup1
    guest ip address 192.168.0.2 255.255.255.0
  &lt;FONT color="#0000FF"&gt;activate&lt;/FONT&gt;&lt;/PRE&gt;
&lt;PRE&gt;My management Interface ge0/0/0&lt;BR /&gt; R1(conf)# inter ge0/0/0&lt;BR /&gt; R1(conf-inter)#ip vrf forward MGT&lt;BR /&gt; R1(conf-inter)#ip address 192.168.200.14 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;My Nmap PC with Ip address 10.10.10.2/24/GW 10.10.0.1 connect to Interface ge0/0/1 with Ip address of &lt;BR /&gt;10.10.0.1.&lt;BR /&gt;&lt;BR /&gt;I ran nmap scan and using command &lt;BR /&gt;show utd engine standard logging event // show nothing.&lt;BR /&gt;I able to ping my log from Router. It seems to me the Interface VirtualPortGroup1 do not forward &lt;BR /&gt;the data from scan machine ( port ge0/0/1) to Snort Engine. I configured Snort for all interfaces.&lt;BR /&gt;Snort engines is up and running fine.&lt;BR /&gt;&lt;BR /&gt;Questions:&lt;BR /&gt;1) Do you see any issues why SNORT logger would not be logging any of the traffic from my nmap PC?&lt;BR /&gt;2) Would we have to put the interface VirtualPortGroup0 to the same VRF of MGT on interface ge0/0/0?&lt;BR /&gt;&lt;BR /&gt;Please help.&lt;BR /&gt;Thank you&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 15:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820253#M42569</guid>
      <dc:creator>tdinh6731</dc:creator>
      <dc:date>2019-03-15T15:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Snort IPS</title>
      <link>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820418#M42570</link>
      <description>&lt;PRE&gt;nmap scan&lt;/PRE&gt;
&lt;P&gt;what command you scan ? what what is the IP address rance you scanned ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2019 21:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820418#M42570</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-03-15T21:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: Snort IPS</title>
      <link>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820980#M42571</link>
      <description>&lt;P&gt;Thank you very, very much for your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Nmap PC, I ran couple cpmmands:&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;1) nmap -A -T4 10.10.0.1&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2) nmap -sT 10.10.0.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2019 22:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort-ips/m-p/3820980#M42571</guid>
      <dc:creator>tdinh6731</dc:creator>
      <dc:date>2019-03-17T22:31:08Z</dc:date>
    </item>
  </channel>
</rss>

