<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP SSM-10 setup and testing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107840#M54294</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;From the PC through the Switch to the Firewall and then back to a second network (VLAN interface) on the switch.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;There is no event or log entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was using Ping -S 0.0.0.0 192.168.1.1 and expected the IDS to pick up the bogus source.&lt;/P&gt;&lt;P&gt;I also tried a standard ping, no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the CLI for the IDS, under show statistics virtural interface, I found "total packets processed since last reset = 0"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Dec 2012 17:46:26 GMT</pubDate>
    <dc:creator>jimmyc_2</dc:creator>
    <dc:date>2012-12-17T17:46:26Z</dc:date>
    <item>
      <title>AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107836#M54286</link>
      <description>&lt;P&gt;In my lab, I have a new 5510 with AIP-SSM card. &lt;/P&gt;&lt;P&gt;I &lt;A&gt;&lt;/A&gt;believe it is configured correctly to evaluate traffic, but I can't be sure.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of the ASA config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; match any&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map&amp;nbsp; global-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class&amp;nbsp; inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect ftp, etc,&lt;/P&gt;&lt;P&gt;&amp;nbsp; class global-class &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ips inline fail-open&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PC going to a switch, going to the ASA (inside interface)&lt;/P&gt;&lt;P&gt;The ASA outside interface is going to a seperate VLAN on the switch.&lt;/P&gt;&lt;P&gt;Both have VLAN interfaces configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a ping command, or other traffic that I can generate from the PC that will throw an alert?&lt;/P&gt;&lt;P&gt;I tried Ping -S from a bogus addresses, but that didn't cause an event.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I know if traffic is actually going through the IDS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107836#M54286</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2019-03-10T12:51:04Z</dc:date>
    </item>
    <item>
      <title>AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107837#M54288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You must assigned a virtual sensor to the interface that connects the AIP-SSM to the ASA ( this must be done on the AIP-SSM, you could use either the GUI or the CLI to make it happen)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now to test it you can use the signature ID 2004 witch is related to ICMP Echo packets.... Enabled it as its disabled by default and on the actions set it to generate an alert,, Then go to monitoring and get a report on the last minute, hour, etc. to get this log and make sure the AIP-SSM is up and ready to protect you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Dec 2012 01:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107837#M54288</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-15T01:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107838#M54290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Configuration&amp;gt;IDS&amp;gt;Interfaces, G0/1 is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have turned on ID 2004.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under the IME menu&amp;nbsp; Home&amp;gt;Device Details:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; G0/0&amp;nbsp; Link=UP, Enabled=Yes, Mode=(blank), Rcd and Xmit are incrementing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; G0/1Link=UP, Enabled=Yes, Mode=unpaired, Rcd and Xmit are incrementing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did not order maintenance, so I have no License.&amp;nbsp; (I'm hoping I only need this to get latest updates and support, not to run the device??)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still have no alerts.&amp;nbsp;&amp;nbsp;&amp;nbsp; How do I generate them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 15:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107838#M54290</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2012-12-17T15:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107839#M54292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good, have you try to ping across your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 17:34:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107839#M54292</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-17T17:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107840#M54294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;From the PC through the Switch to the Firewall and then back to a second network (VLAN interface) on the switch.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;There is no event or log entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was using Ping -S 0.0.0.0 192.168.1.1 and expected the IDS to pick up the bogus source.&lt;/P&gt;&lt;P&gt;I also tried a standard ping, no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the CLI for the IDS, under show statistics virtural interface, I found "total packets processed since last reset = 0"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 17:46:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107840#M54294</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2012-12-17T17:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107841#M54295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jimmy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Share the following from the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show service policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 17:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107841#M54295</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-18T17:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107842#M54296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Service-policy:&amp;nbsp; global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; Class-map:&amp;nbsp;&amp;nbsp; inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect:&amp;nbsp; DNS, FTP, H233, etc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (all zeros)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Class-map:&amp;nbsp; global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS:&amp;nbsp; Card status UP, mode inline fail-open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet input 0, Packet output 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind that I only have one PC and one switch (with two VLAN interfaces) attached.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 20:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107842#M54296</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2012-12-18T20:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: AIP SSM-10 setup and testing</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107843#M54297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jimmy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;lass-map:&amp;nbsp; global-class&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS:&amp;nbsp; Card status UP, mode inline fail-open&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet input 0, Packet output 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No packets are getting to the IPS module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You told me is assigned to Virtual sensor 0 on the AIP-SSM right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 21:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-10-setup-and-testing/m-p/2107843#M54297</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-12-18T21:29:41Z</dc:date>
    </item>
  </channel>
</rss>

