<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS slows down internet access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305632#M53458</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We still have this issue in our network. I see the following errors in IPS this time: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=6822257491706&amp;nbsp; vendor=Cisco&amp;nbsp; severity=error&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; originator:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: &lt;IPSHOSTNAME&gt;&amp;nbsp; &lt;/IPSHOSTNAME&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: cidwebserver&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 1458&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; time: Aug 31, 2013 09:08:36 UTC&amp;nbsp; offset=180&amp;nbsp; timeZone=GMT+03:00&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; errorMessage: Throttled connect timed out [ClientPipe::connect]&lt;/P&gt;&lt;P&gt;Messages, like this one, in the category - Connect timeout - were logged 12 times in the last 72492 seconds.&amp;nbsp; name=errSystemError&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=6822257491707&amp;nbsp; vendor=Cisco&amp;nbsp; severity=error&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; originator:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: &lt;IPSHOSTNAME&gt;&lt;/IPSHOSTNAME&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: cidwebserver&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 1458&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; time: Aug 31, 2013 09:08:36 UTC&amp;nbsp; offset=180&amp;nbsp; timeZone=GMT+03:00&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; errorMessage: - ct-sensorApp.1475 not responding, please check system processes - The connect to the specified Io::ClientPipe failed.&lt;/P&gt;&lt;P&gt;Messages, like this one, in the category - ctlTrans Timeout - were logged 12 times in the last 72492 seconds.&amp;nbsp; name=errSystemError&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;It appears that the sensorApp is not responding. Can anyone assist. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 31 Aug 2013 15:55:16 GMT</pubDate>
    <dc:creator>ahamadfaiz</dc:creator>
    <dc:date>2013-08-31T15:55:16Z</dc:date>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305626#M53452</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an IPS&lt;SPAN style="font-size: 10pt;"&gt;4270-20-K9 appliance monitoring our DMZ network and INSIDE segment. There are two virutal sensors with different Signature Definiton and Event Action Rules policies for each segment. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;We recently updated software version from 7.0(2)E4 to version 7.1(7)E4. Ever since we have issues with internet access. We are unable to access sites like Google, Youtube etc (yeah these are allowed through our network). Youtube page opens but the streaming does not happen. We were suspecting our proxy or ISP as it was a few sites that does not work. However, we tested the sites by directly connecting to our internet router and it worked fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Then we tested by bypassing IPS inspection by changin Bypass Merode in to Off. Everything works just fine then. We did this for a few times while the sites were not accessible and it gave the same result.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;When I check the instpection-load it is always below 25. The CPU shows close to 100% all the time, but the Cisco says it is not the correct measure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Have anyone faced similar issue. Please assist with this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Faiz&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305626#M53452</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2019-03-10T13:02:47Z</dc:date>
    </item>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305627#M53453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additional investigation shows that the signature &lt;SPAN style="font-size: 10pt;"&gt;TCP Drop - RST or SYN in Window is getting triggered in huge numbers. The traffic is from external IP addresses to Proxy IP, which is obviously for return traffic from internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The signature description says that "&lt;/SPAN&gt;&lt;EM style="font-size: 10pt;"&gt;If a packet in a stream causes this signature to produce an alert, processing will cease for that stream&lt;/EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect that is causing this issue. Please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Aug 2013 10:01:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305627#M53453</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-08-26T10:01:24Z</dc:date>
    </item>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305628#M53454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faiz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have almost same issue, but looks like symptoms are different, our download speed is not so bad, but upload speed is incredibly slow, even not uploading and dropping everything, we having 4240 and it was happend 2 weeks ago after updated latest signature but still find the real cause, in my case if we put Bypass mode it having same result, but looks like you having different situation, you need to check the Signature ID and maybe can disable them and see. Any TAC created?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 02:32:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305628#M53454</guid>
      <dc:creator>TM13</dc:creator>
      <dc:date>2013-08-27T02:32:09Z</dc:date>
    </item>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305629#M53455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="font-size: 10pt;"&gt;Tulgabat,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you for the reply.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I am yet to dig deep in to the event and signature. I hope I can get more info then.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;However, we have identifed a common user ID that has been misused. This user was accesging youtube and such streaming sites extensively. We have now disabled this user and we have not faced this issue after that. However, we cannot conclude anything yet because this issue is intermittend and we need wait for a few days to see if that has helped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 08:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305629#M53455</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-08-27T08:28:42Z</dc:date>
    </item>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305630#M53456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faiz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like you may have been able to isolate the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For future reference, if you would like to keep this signature (1330-14 in this case) enabled on the IPS for all of your other hosts but want it tuned to not alert on the particular proxy host, you could add an event action rule for the internal proxy for this particular signature and subtract the produce alert from the action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Via IDM &lt;/P&gt;&lt;P&gt;Configuration -&amp;gt; Event Action Rules -&amp;gt; rules0 -&amp;gt; Even Action Filters &lt;/P&gt;&lt;P&gt;+ Add&lt;/P&gt;&lt;P&gt;Name your filter. Add the proxy as the destination. Fill in the other needed fields. -&amp;gt; Action to Subtract -&amp;gt; remove any of the alert variables. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is really helpful when you are first placing an IPS in place and/or when you are adding new networks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Aug 2013 14:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305630#M53456</guid>
      <dc:creator>largenb</dc:creator>
      <dc:date>2013-08-27T14:50:45Z</dc:date>
    </item>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305631#M53457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi William,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am aware of event action filters and have a few created already.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I wanted to know why this signature is getting triggered in the first place. Moreover, it does not process the traffic if the signature triggers for a stream. I am trying to undestand what causes this. Especially for streaming traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please assist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Aug 2013 09:22:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305631#M53457</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-08-28T09:22:01Z</dc:date>
    </item>
    <item>
      <title>IPS slows down internet access</title>
      <link>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305632#M53458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We still have this issue in our network. I see the following errors in IPS this time: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=6822257491706&amp;nbsp; vendor=Cisco&amp;nbsp; severity=error&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; originator:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: &lt;IPSHOSTNAME&gt;&amp;nbsp; &lt;/IPSHOSTNAME&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: cidwebserver&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 1458&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; time: Aug 31, 2013 09:08:36 UTC&amp;nbsp; offset=180&amp;nbsp; timeZone=GMT+03:00&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; errorMessage: Throttled connect timed out [ClientPipe::connect]&lt;/P&gt;&lt;P&gt;Messages, like this one, in the category - Connect timeout - were logged 12 times in the last 72492 seconds.&amp;nbsp; name=errSystemError&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=6822257491707&amp;nbsp; vendor=Cisco&amp;nbsp; severity=error&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; originator:&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: &lt;IPSHOSTNAME&gt;&lt;/IPSHOSTNAME&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: cidwebserver&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 1458&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; time: Aug 31, 2013 09:08:36 UTC&amp;nbsp; offset=180&amp;nbsp; timeZone=GMT+03:00&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; errorMessage: - ct-sensorApp.1475 not responding, please check system processes - The connect to the specified Io::ClientPipe failed.&lt;/P&gt;&lt;P&gt;Messages, like this one, in the category - ctlTrans Timeout - were logged 12 times in the last 72492 seconds.&amp;nbsp; name=errSystemError&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;It appears that the sensorApp is not responding. Can anyone assist. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Faiz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Aug 2013 15:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-slows-down-internet-access/m-p/2305632#M53458</guid>
      <dc:creator>ahamadfaiz</dc:creator>
      <dc:date>2013-08-31T15:55:16Z</dc:date>
    </item>
  </channel>
</rss>

