<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Event Action Filter is not working properly. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438561#M45799</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input Diego.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the IP as you've suggested, but no difference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 Feb 2014 15:22:34 GMT</pubDate>
    <dc:creator>Mariusz Bochen</dc:creator>
    <dc:date>2014-02-19T15:22:34Z</dc:date>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438557#M45771</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have a local syslog server which listens on UDP 514 port. As many UDP frames has been cut I've done some investigation and found dropped packets (action requested by IPS). This was 1206.0 signature which is "IP Fragmant Too Small". I have created a new entry in IPS Policies to filter this out, but it didn't help. As a test I have disabled the signature completly and all frames have been delivered fine. Another thing I've tried was bringing the new action filter to the top and enabled "Stop on Match" option. Still the same. The only one solution is to disable the signature, but we can't do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is ASA-SSM-20 installed on ASA 5520 version 7.1(6)E4, mode: inline&lt;/P&gt;&lt;P&gt;Bug search tool didn't show any related bugs.&lt;/P&gt;&lt;P&gt;I have checked Database integrity and get "No errors found while performing database integrity checks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;1. What can cause an action to be ignored on IPS?&lt;/P&gt;&lt;P&gt;2. Is it worth to use "Repair Database" tool? If yes what is the impact.&lt;/P&gt;&lt;P&gt;3. Is it possible to check hit counts on each action filter?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mariusz&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438557#M45771</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2019-03-10T13:08:39Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438558#M45783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By default, the Summarizer is enabled. If you disable it, all signatures&amp;nbsp; are set to Fire All with no summarization. If you configure individual&amp;nbsp; signatures to summarize, this configuration will be ignored if the&amp;nbsp; Summarizer is not enabled. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Feb 2014 07:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438558#M45783</guid>
      <dc:creator>Naveen Kumar</dc:creator>
      <dc:date>2014-02-13T07:29:13Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438559#M45790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;Summarizer is enabled. All signature settings are left as default.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 15:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438559#M45790</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2014-02-18T15:36:19Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438560#M45795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just for a test..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside the Sensor Management, Blocking, Blocking Properties.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add the IP as Never Block, just for a test..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, Dont you think that you should update your version?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 16:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438560#M45795</guid>
      <dc:creator>Diego Maciel Gomes</dc:creator>
      <dc:date>2014-02-18T16:36:48Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438561#M45799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input Diego.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the IP as you've suggested, but no difference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 15:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438561#M45799</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2014-02-19T15:22:34Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438562#M45802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hum... Very weird, I never see it before!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you have a missmatch configuration, like, something is not matching with anything so, the filter does not apply..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know you did, but, maybe a new double-check in the configuration? Src Addr, Signature ID... Is everything correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 15:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438562#M45802</guid>
      <dc:creator>Diego Maciel Gomes</dc:creator>
      <dc:date>2014-02-19T15:45:26Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438563#M45807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Filter settings below:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/7/9/180971-filter.jpg" alt="filter.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The filter works &lt;SPAN style="font-size: 10pt;"&gt;partially &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;as I don't get alerts on the IPS itself.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall LOG:&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Feb 14 2014&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;15:33:22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SOURCE_HOST&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;39715&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;DESTINATION_HOST&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;514&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;IPS requested to drop UDP packet from SOURCE_VLAN_NUMBER:&lt;SOURCE_HOST&gt;/39715 to DESTINATION_VLAN_NUMBER:&lt;DESTINATION_HOST&gt;/514&lt;/DESTINATION_HOST&gt;&lt;/SOURCE_HOST&gt;&lt;/DESTINATION_HOST&gt;&lt;/SOURCE_HOST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS LOG (when enabled):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1352793300955167909&amp;nbsp; vendor=Cisco&amp;nbsp; severity=low&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; originator:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: SSM02&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: sensorApp&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 1192&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; time: Feb 14, 2014 15:33:22 UTC&amp;nbsp; offset=0&amp;nbsp; timeZone=GMT00:00&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; signature:&amp;nbsp;&amp;nbsp; description=IP Fragment Too Small&amp;nbsp; id=1206&amp;nbsp; version=S212&amp;nbsp; type=anomaly&amp;nbsp; created=20030801&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subsigId: 0&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sigDetails: Too many small IP fragments in datagram&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; interfaceGroup: vs0&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; vlan: 0&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; participants:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; attacker:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; addr: 172.x.x.x&amp;nbsp; locality=OUT&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port: 39715&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; target:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; addr: x.x.x.x&amp;nbsp; locality=OUT&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port: 514&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; os:&amp;nbsp;&amp;nbsp; idSource=unknown&amp;nbsp; type=unknown&amp;nbsp; relevance=relevant&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; alertDetails: InterfaceAttributes:&amp;nbsp; context="single_vf" physical="Unknown" backplane="GigabitEthernet0/1" ;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; riskRatingValue: 50&amp;nbsp; targetValueRating=medium&amp;nbsp; attackRelevanceRating=relevant&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; threatRatingValue: 50&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; interface: GigabitEthernet0/1&amp;nbsp; context=single_vf&amp;nbsp; physical=Unknown&amp;nbsp; backplane=GigabitEthernet0/1&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol: udp&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our next step is to make a service policy exception on the firewall itself. We are also considering reloading the IPS device or at least the analysis engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your help so far. &lt;SPAN style="font-size: 10pt;"&gt;Any more suggestions are most welcome. I'll keep you up to date.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Mariusz&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 12:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438563#M45807</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2014-02-20T12:06:43Z</dc:date>
    </item>
    <item>
      <title>IPS Event Action Filter is not working properly.</title>
      <link>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438564#M45810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;I configured the service policy rule on the firewall to bypass IPS. Still the same.&lt;/P&gt;&lt;P&gt;The only one option which works is to disable the signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any more ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mariusz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Mar 2014 15:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-event-action-filter-is-not-working-properly/m-p/2438564#M45810</guid>
      <dc:creator>Mariusz Bochen</dc:creator>
      <dc:date>2014-03-03T15:14:57Z</dc:date>
    </item>
  </channel>
</rss>

