<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Verify IPS setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/verify-ips-setup/m-p/2241052#M53776</link>
    <description>&lt;P&gt;I am very new to the Cisco IPS front and have setup a ASA 5510 with the SSM-10 IPS module.&amp;nbsp; We have one interface enabled with multiple VLANs on this interface.&amp;nbsp; I have setup the IPS, to the best of my abilities, and I believe it is correct as inline fail open in an active/standby asa setup.&amp;nbsp; Is there any way to verify that traffic is flowing properly to this IPS module?&amp;nbsp; Also, the reason I mentioned out setup is because this IPS version, as I understand it, will not allow for VLAN pairs, so when I set the policy to inspect all traffic, is this traffic inspected between all VLANs.&amp;nbsp; One other mystery is that when I view my IPS interfaces (one management and one not)&amp;nbsp; the one that is not setup as management is showing unpaired.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this was a lot, so let me recap:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- How do I verify my setup is functioning as inteded where all traffic between all VLANs is being inspected.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;- Why is my non-management interface showing "unpaired"&lt;/P&gt;&lt;P&gt;- Looking through all the Cisco documentation, I noticed mention of "contexts"; I don't see any reference to these contexts within the IDM.&amp;nbsp; This is just for my knowledge, but maybe necessary for the setup...I just don't know.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:57:55 GMT</pubDate>
    <dc:creator>Heath Mote</dc:creator>
    <dc:date>2019-03-10T12:57:55Z</dc:date>
    <item>
      <title>Verify IPS setup</title>
      <link>https://community.cisco.com/t5/network-security/verify-ips-setup/m-p/2241052#M53776</link>
      <description>&lt;P&gt;I am very new to the Cisco IPS front and have setup a ASA 5510 with the SSM-10 IPS module.&amp;nbsp; We have one interface enabled with multiple VLANs on this interface.&amp;nbsp; I have setup the IPS, to the best of my abilities, and I believe it is correct as inline fail open in an active/standby asa setup.&amp;nbsp; Is there any way to verify that traffic is flowing properly to this IPS module?&amp;nbsp; Also, the reason I mentioned out setup is because this IPS version, as I understand it, will not allow for VLAN pairs, so when I set the policy to inspect all traffic, is this traffic inspected between all VLANs.&amp;nbsp; One other mystery is that when I view my IPS interfaces (one management and one not)&amp;nbsp; the one that is not setup as management is showing unpaired.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this was a lot, so let me recap:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- How do I verify my setup is functioning as inteded where all traffic between all VLANs is being inspected.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;- Why is my non-management interface showing "unpaired"&lt;/P&gt;&lt;P&gt;- Looking through all the Cisco documentation, I noticed mention of "contexts"; I don't see any reference to these contexts within the IDM.&amp;nbsp; This is just for my knowledge, but maybe necessary for the setup...I just don't know.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/verify-ips-setup/m-p/2241052#M53776</guid>
      <dc:creator>Heath Mote</dc:creator>
      <dc:date>2019-03-10T12:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Verify IPS setup</title>
      <link>https://community.cisco.com/t5/network-security/verify-ips-setup/m-p/2241053#M53777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Heat Mote,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- How do I verify my setup is functioning as inteded where all traffic between all VLANs is being inspected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you are using an IPS module,&amp;nbsp; the traffic matched by the class configued on the ASA is the one being inspected, you can set up a capture on the dataplane Interface (Interface used to send traffic from the ASA to IPS) using this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture ips int asa_dataplane buffer 15000000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify the capture by using:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show capture ips&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output should display packets from every VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Why is my non-management interface showing "unpaired"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; text-indent: -28.799999237060547px; background-color: #ffffff;" width="1" /&gt;&lt;/P&gt;&lt;P&gt;The ASA IPS modules (ASA 5500 AIP SSM, ASA 5500-X IPS SSP, and ASA 5585-X IPS SSP) do not support inline VLAN pairs. &lt;/P&gt;&lt;P&gt;You can associate VLANs in pairs on a physical interface. This is known as inline VLAN pair mode. Packets received on one of the paired VLANs are analyzed and then forwarded to the other VLAN in the pair. Since the module only has one sensing interface, that is why it is shown as Unpaired. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation is talking about "security contexts". &lt;SPAN style="font-size: 10pt;"&gt;You can partition a single ASA into multiple virtual devices, known as security contexts. Each context is an independent device, with its own security policy, interfaces, and administrators. Multiple contexts are similar to having multiple standalone devices. Many features are supported in multiple context mode, including routing tables, firewall features, IPS, and management.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate the answer if you find it useful. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 01:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/verify-ips-setup/m-p/2241053#M53777</guid>
      <dc:creator>Eddy Duran</dc:creator>
      <dc:date>2013-05-17T01:04:25Z</dc:date>
    </item>
  </channel>
</rss>

