<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSM-AIP function in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087429#M54238</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it should, but it needs to be configured. Have you checked if the logging is still enabled? Can you verify if the ASA is sending IPS traffic to the AIP? please refer to below link for configuring AIP on ASA. &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/clissm.pdf"&gt;http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/clissm.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Jan 2013 10:24:15 GMT</pubDate>
    <dc:creator>Rudy Sanjoko</dc:creator>
    <dc:date>2013-01-07T10:24:15Z</dc:date>
    <item>
      <title>SSM-AIP function</title>
      <link>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087428#M54237</link>
      <description>&lt;P&gt;I've just had a TAC opened and the technician did some global inspection rule and a ping test from internal server to the firewall/IPS and we saw the event.&amp;nbsp;&amp;nbsp; A few weeks have passed and none of the reports have any data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've ran a NeXpose vulnerability scanner from inside against the firewall's internal IP and ran NeXpose from the outside against multiple firewall's IPs.&amp;nbsp; I still don't see any events in the IDM, IPS Manager Express, or the ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shouldn't the vulnerability scanner trigger the IPS internally and externally?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087428#M54237</guid>
      <dc:creator>itlibrary</dc:creator>
      <dc:date>2019-03-10T12:51:51Z</dc:date>
    </item>
    <item>
      <title>SSM-AIP function</title>
      <link>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087429#M54238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it should, but it needs to be configured. Have you checked if the logging is still enabled? Can you verify if the ASA is sending IPS traffic to the AIP? please refer to below link for configuring AIP on ASA. &lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/clissm.pdf"&gt;http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/clissm.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2013 10:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087429#M54238</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2013-01-07T10:24:15Z</dc:date>
    </item>
    <item>
      <title>SSM-AIP function</title>
      <link>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087430#M54240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where do I check to see if logging is still enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've enabled rule 2000 and 2004 for ICMP and I do see ICMP Echo Request and ICMP Echo Reply in IME Event View when I ping google.com from the inside.&amp;nbsp; When I run NeXpsoe scanner against the firewall from inside and outside, there are no events displayed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2013 13:43:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087430#M54240</guid>
      <dc:creator>itlibrary</dc:creator>
      <dc:date>2013-01-07T13:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSM-AIP function</title>
      <link>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087431#M54242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are saying that you can see ICMP traffic but no event being generated from nmap, that makes me think that perhaps your IPS has been tuned to ignores the alerts from the nexpose in your network, I'm not so sure how you configured it but here is on how to tuning it, please verify if you have deployed and configured it correctly, also check your ips policies and signature file,&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/overview_c17-464691_ps6120_Products_White_Paper.html" rel="nofollow"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/overview_c17-464691_ps6120_Products_White_Paper.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2013 14:21:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087431#M54242</guid>
      <dc:creator>Rudy Sanjoko</dc:creator>
      <dc:date>2013-01-07T14:21:48Z</dc:date>
    </item>
    <item>
      <title>SSM-AIP function</title>
      <link>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087432#M54244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ping Firewall produces no events&lt;/P&gt;&lt;P&gt;Ping Google.com produces ICMP events&lt;/P&gt;&lt;P&gt;No specific Policy or rule for NeXpose scanner or it's IP address.&lt;/P&gt;&lt;P&gt;Logging is enabled&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jan 2013 15:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssm-aip-function/m-p/2087432#M54244</guid>
      <dc:creator>itlibrary</dc:creator>
      <dc:date>2013-01-07T15:44:14Z</dc:date>
    </item>
  </channel>
</rss>

