<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS IPS - Reset Conection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309976#M53354</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rodolfo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Totally agree with you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reopen the TAC case and push for a fix or at least an explanation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Oct 2013 22:06:31 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-10-11T22:06:31Z</dc:date>
    <item>
      <title>IOS IPS - Reset Conection</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309971#M53334</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;IOS IPS was configured to only generate alert. During testing it was observed that the IPS was reset in giving connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;log below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;SPAN style="color: #ff0000;"&gt;*Oct 10 14:30:29: %IPS-6-SEND_TCP_PAK: Sending TCP packet:(X.X.X.X:433)=&amp;gt;(y.y.y.y:63170),tcp flag:0x4, pak:0x2166449C, iso:0x3D5C7160,tcp seq:0x0, tcp ack:0x0, tcp_window:8192, ip_checksum:0x44B8, Serial0/0/0.1,feat_flags:0x10000, fast_path(no)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some time ago cisco identified a bug in earlier versions. After opening some TAC, suggested upgrading the IOS and subscription packages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco recommendation below: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&lt;SPAN style="color: #ff0000;"&gt;IOS Version : c2900-universalk9-mz.SPA.153-3.M.bin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Helvetica; font-size: 12px; color: #ff0000;"&gt; Packet sig: OS-S744-CLI.pkg&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration Cisco Router &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;ip ips config location flash:ips retries 1&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;ip ips notify SDEE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Helvetica; font-size: 12px;"&gt;ip ips name iosips&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;!&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;ip ips signature-category &lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&amp;nbsp; category all&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&amp;nbsp;&amp;nbsp; retired true&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&amp;nbsp; category ios_ips basic&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica;"&gt;&amp;nbsp;&amp;nbsp; retired false&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Helvetica; color: #e32400;"&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;event-action produce-alert&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone tell how to solve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BestRegards &lt;/P&gt;&lt;P&gt;Rodolfo Navero &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:04:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309971#M53334</guid>
      <dc:creator>Rodolfo Navero</dc:creator>
      <dc:date>2019-03-10T13:04:07Z</dc:date>
    </item>
    <item>
      <title>IOS IPS - Reset Conection</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309972#M53336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rodolfo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So are you saying you did the upgrade as TAC requested and are still facing the same issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the BUG ID?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 21:27:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309972#M53336</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-10T21:27:16Z</dc:date>
    </item>
    <item>
      <title>IOS IPS - Reset Conection</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309973#M53342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, just follow the request of the TAC, have BUG ID number &lt;SPAN style="background-color: #f7fafb; font-size: 12px;"&gt;ID : &lt;/SPAN&gt;&lt;A href="http://cdets.cisco.com/apps/dumpcr?&amp;amp;content=summary&amp;amp;format=html&amp;amp;identifier=CSCty10906" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681; text-decoration: none;" target="_blank"&gt;CSCty10906&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The strange thing is that IPS does not match the signature effects, making it impossible to identify the event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;Rodolfo Navero&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Oct 2013 23:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309973#M53342</guid>
      <dc:creator>Rodolfo Navero</dc:creator>
      <dc:date>2013-10-10T23:02:32Z</dc:date>
    </item>
    <item>
      <title>IOS IPS - Reset Conection</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309974#M53346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rodolfo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see what you mean.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You get something like :&lt;/P&gt;&lt;P&gt;%IPS-6-SEND_TCP_PAK:&lt;/P&gt;&lt;P&gt;&lt;BR style="line-height: 11px; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ffeeee;" /&gt;&lt;/P&gt;&lt;P&gt;and &lt;/P&gt;&lt;P&gt;&lt;BR style="line-height: 11px; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ffeeee;" /&gt;&lt;/P&gt;&lt;P&gt;%IPS-6-TIMEOUT_EVENT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the only workaround I know is the following:&lt;/P&gt;&lt;P&gt;ip ips tunables alert-off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which will turn those alerts off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 04:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309974#M53346</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-11T04:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS - Reset Conection</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309975#M53348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But it will make the warnings go away, right?&lt;/P&gt;&lt;P&gt;but still see the reset command sh ip ips statics.&lt;/P&gt;&lt;P&gt;It seems the problem is in the subsystem of the feature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used up the hidden command on the router, but not solved the problem.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;csdb tcp&amp;nbsp; reassembly max-queue-length&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interfaces configured for ips 1&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Session creations since subsystem startup or last reset 240&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [7:17:0]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [10:59:1]&lt;/P&gt;&lt;P&gt;Last session created 00:00:01&lt;/P&gt;&lt;P&gt;Last statistic reset 00:04:15&lt;/P&gt;&lt;P&gt;TCP reassembly statistics&lt;/P&gt;&lt;P&gt;&amp;nbsp; Out-of-order packets dropped 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++++++++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;I performed some tests.&lt;/P&gt;&lt;P&gt;When I make disable all signatures, presents no reset.&lt;/P&gt;&lt;P&gt;However when I enable a single signature, the reset continues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe Cisco has a bug in the compilation of feature&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;sh ip ips statistics&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;Interfaces configured for ips 1&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;Session creations since subsystem startup or last reset 0&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;Current session counts (estab/half-open/terminating) [4:3:0]&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;Maxever session counts (estab/half-open/terminating) [4:3:0]&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;Last session created 00:23:36&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;Last statistic reset 00:15:40&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;TCP reassembly statistics&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; color: #000000; text-align: -webkit-auto;"&gt;&amp;nbsp; Out-of-order packets dropped 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Rodolfo Navero&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 11:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309975#M53348</guid>
      <dc:creator>Rodolfo Navero</dc:creator>
      <dc:date>2013-10-11T11:46:34Z</dc:date>
    </item>
    <item>
      <title>IOS IPS - Reset Conection</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309976#M53354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rodolfo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Totally agree with you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My recommendation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reopen the TAC case and push for a fix or at least an explanation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jcarvaja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 22:06:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-reset-conection/m-p/2309976#M53354</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-10-11T22:06:31Z</dc:date>
    </item>
  </channel>
</rss>

