<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anomaly Detection not detecting host machines (learned OS) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459755#M45620</link>
    <description>&lt;P&gt;I have an ASA5540X firewall with the internal (software based) IPS module. The module has the up-to-date signatures and seems to be running correctly. However, after enabling anomaly detection (ad0), and specifying the internal zones, I don't see any "Learned OS" in IME&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My settings are pretty basic for the sensor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list ips_traffic extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list ips_traffic extended permit udp any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map ips_class&lt;/P&gt;&lt;P&gt;&amp;nbsp;match access-list ips_traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;class ips_class&lt;/P&gt;&lt;P&gt;&amp;nbsp;ips inline fail-open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why it isn't learning the OSs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:10:56 GMT</pubDate>
    <dc:creator>Colin Higgins</dc:creator>
    <dc:date>2019-03-10T13:10:56Z</dc:date>
    <item>
      <title>Anomaly Detection not detecting host machines (learned OS)</title>
      <link>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459755#M45620</link>
      <description>&lt;P&gt;I have an ASA5540X firewall with the internal (software based) IPS module. The module has the up-to-date signatures and seems to be running correctly. However, after enabling anomaly detection (ad0), and specifying the internal zones, I don't see any "Learned OS" in IME&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My settings are pretty basic for the sensor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list ips_traffic extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list ips_traffic extended permit udp any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map ips_class&lt;/P&gt;&lt;P&gt;&amp;nbsp;match access-list ips_traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;class ips_class&lt;/P&gt;&lt;P&gt;&amp;nbsp;ips inline fail-open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why it isn't learning the OSs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459755#M45620</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-10T13:10:56Z</dc:date>
    </item>
    <item>
      <title>Learned OS maps—OS maps</title>
      <link>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459756#M45623</link>
      <description>&lt;P&gt;Learned OS maps—OS maps observed by the sensor through the fingerprinting of TCP packets with the SYN control bit set. Learned OS maps are local to the virtual sensor that sees the traffic.&lt;/P&gt;&lt;P&gt;can you verify the OS finger printing from&lt;/P&gt;&lt;P&gt;sensor# show os-identification learned&lt;/P&gt;&lt;P&gt;Enable &lt;STRONG&gt;passive-traffic-analysis {enabled | disabled}&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 05:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459756#M45623</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-04-11T05:56:33Z</dc:date>
    </item>
    <item>
      <title>I realized that the problem</title>
      <link>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459757#M45625</link>
      <description>&lt;P&gt;I realized that the problem was a failover issue--the ASAs are in a pair, and after a failover, the IPS policies had been applied to the wrong (failover) IPS module. Once I applied them on the correct module, I could see all the learned OSs.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 14:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anomaly-detection-not-detecting-host-machines-learned-os/m-p/2459757#M45625</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-04-11T14:19:07Z</dc:date>
    </item>
  </channel>
</rss>

