<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you don't want IPS to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460783#M45624</link>
    <description>&lt;P&gt;If you don't want IPS to block any thing sitting inline but throw alert, from the event actions opt "produce alert"&lt;/P&gt;&lt;P class="pB1_Body1"&gt;Produce Alert&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062312" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;Writes the event to the Event Store as an alert.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1074480" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;B&gt;Note &lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="1" /&gt;The Produce Alert action is not automatic when you enable alerts for a signature. To have an alert created in the Event Store, you must select Produce Alert. If you add a second action, you must include Produce Alert if you want an alert sent to the Event Store. Also, every time you configure the event actions, a new list is created and it replaces the old list. Make sure you include all the event actions you need for each signature.&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ips_produce_alert_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Apr 2014 06:31:11 GMT</pubDate>
    <dc:creator>Saurav Lodh</dc:creator>
    <dc:date>2014-04-11T06:31:11Z</dc:date>
    <item>
      <title>Configure newly deployed inline IPS to alert only</title>
      <link>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460781#M45621</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;I'm hoping some of you experts can assist me with this request. Recently started a new job and they put the IPS into prod &amp;nbsp;(We are running the software based module on our ASA.)&amp;nbsp;and it started blocking more then they had intended. They configured the ASA to not send any traffic to it, to stop the outage.&lt;/P&gt;&lt;P&gt;So now we have an IPS half-way setup and I need to finish the job. I'm new to Cisco IPS, but I really want to know is there a way I can deploy this sensor so that it is still inline but it will not block anything. This way I can baseline the environment and see what type of alerts are firing?&lt;/P&gt;&lt;P&gt;Any help on the best to set this up / deploy tips would be appreciated!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460781#M45621</guid>
      <dc:creator>savy-pfsec</dc:creator>
      <dc:date>2019-03-10T13:10:59Z</dc:date>
    </item>
    <item>
      <title>Refer this link to set up</title>
      <link>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460782#M45622</link>
      <description>&lt;P&gt;Refer this link to set up your ips module:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/asdm70/configuration_guide/asdm_70_config/modules_ips.html.&lt;/P&gt;&lt;P&gt;Better you deploy ips module in promiscuous mode if you don't want to block any traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 06:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460782#M45622</guid>
      <dc:creator>Poonam Garg</dc:creator>
      <dc:date>2014-04-11T06:07:46Z</dc:date>
    </item>
    <item>
      <title>If you don't want IPS to</title>
      <link>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460783#M45624</link>
      <description>&lt;P&gt;If you don't want IPS to block any thing sitting inline but throw alert, from the event actions opt "produce alert"&lt;/P&gt;&lt;P class="pB1_Body1"&gt;Produce Alert&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062312" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;Writes the event to the Event Store as an alert.&lt;/P&gt;&lt;P&gt;&lt;A name="wp1074480" style="text-decoration: none;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;B&gt;Note &lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="1" /&gt;The Produce Alert action is not automatic when you enable alerts for a signature. To have an alert created in the Event Store, you must select Produce Alert. If you add a second action, you must include Produce Alert if you want an alert sent to the Event Store. Also, every time you configure the event actions, a new list is created and it replaces the old list. Make sure you include all the event actions you need for each signature.&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/ips_produce_alert_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P class="pNT_NoteTable"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 06:31:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460783#M45624</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-04-11T06:31:11Z</dc:date>
    </item>
    <item>
      <title>Poonam and salodh thank you</title>
      <link>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460784#M45626</link>
      <description>&lt;P&gt;Poonam and salodh thank you both for your replies!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Poonam - I was considering deploying it in promiscuous mode, but I had concerns on signatures that were set to "deny packet inline" only in that mode. In that case it would not "block" anything, but would I still see an alert (even thou "produce alert" is not set in the sig) for this event?&lt;/P&gt;&lt;P&gt;salodh - I think this idea is more what i was initially thinking. I have a question on it however. If using an "Event action override" and I check "Produce Alert" in your example attached would it also still deny the packet inline because "Deny packet inline" is also checked?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again thanks for the help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 13:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configure-newly-deployed-inline-ips-to-alert-only/m-p/2460784#M45626</guid>
      <dc:creator>savy-pfsec</dc:creator>
      <dc:date>2014-04-11T13:51:19Z</dc:date>
    </item>
  </channel>
</rss>

