<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic no traffic on IPS promiscuous in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065487#M54445</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a 5545X with 5545-IPS module. It is up, updateing signatures but there are no packets checked on it. On the sensor side I'm confused that hardware/software version is shown as N/A. ASA config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list test extended permit ip interface outside any&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; class-map test-class&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; match access-list test&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; class test-class&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; ips promiscuous fail-open sensor vs0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;service-policy global_policy global&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all &lt;STRONG&gt;show statistics&lt;/STRONG&gt; commands (engine, host, etc) on IPS show 0 in packets so it seems like traffic is not passed to IPS from ASA. Global policy output &lt;/P&gt;&lt;P&gt;on ASA shows the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Global policy:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Service-policy: global_policy&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Class-map: test-class&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;IPS: card status UP, license status Enabled, mode promiscuous fail-open, sensor vs0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; packet input 0, packet output 0, drop 0, reset-drop 0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can prevent global-policy to do it job?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank s&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:48:50 GMT</pubDate>
    <dc:creator>Volodymyr Morskyy</dc:creator>
    <dc:date>2019-03-10T12:48:50Z</dc:date>
    <item>
      <title>no traffic on IPS promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065487#M54445</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a 5545X with 5545-IPS module. It is up, updateing signatures but there are no packets checked on it. On the sensor side I'm confused that hardware/software version is shown as N/A. ASA config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;access-list test extended permit ip interface outside any&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; class-map test-class&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; match access-list test&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;policy-map global_policy&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; class test-class&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; ips promiscuous fail-open sensor vs0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;service-policy global_policy global&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all &lt;STRONG&gt;show statistics&lt;/STRONG&gt; commands (engine, host, etc) on IPS show 0 in packets so it seems like traffic is not passed to IPS from ASA. Global policy output &lt;/P&gt;&lt;P&gt;on ASA shows the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Global policy:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Service-policy: global_policy&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Class-map: test-class&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;IPS: card status UP, license status Enabled, mode promiscuous fail-open, sensor vs0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp; packet input 0, packet output 0, drop 0, reset-drop 0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can prevent global-policy to do it job?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank s&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:48:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065487#M54445</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2019-03-10T12:48:50Z</dc:date>
    </item>
    <item>
      <title>no traffic on IPS promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065488#M54447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the IPS side, is the PortChannel assigned to vs0 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service analysis-engine&lt;/P&gt;&lt;P&gt;virtual-sensor vs0&lt;/P&gt;&lt;P&gt;physical-interface PortChannel0/0&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 05:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065488#M54447</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-11-06T05:12:35Z</dc:date>
    </item>
    <item>
      <title>no traffic on IPS promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065489#M54448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sawan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is assigned. I have no idea why nothing is matched with my policy, and even access-list shows 0 packet counts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Volodymyr&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 09:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065489#M54448</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2012-11-06T09:22:43Z</dc:date>
    </item>
    <item>
      <title>no traffic on IPS promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065490#M54450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could use following sample config on ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map all-traffic-class&lt;/P&gt;&lt;P&gt; match access-list all-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; policy-map pro-fail-open&lt;/P&gt;&lt;P&gt; class all-traffic-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; ips promiscuous fail-open&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection advanced-options tmap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy pro-fail-open global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 12:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065490#M54450</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-11-06T12:43:36Z</dc:date>
    </item>
    <item>
      <title>no traffic on IPS promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065491#M54452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you show access-list all-traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2012 13:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065491#M54452</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2012-11-06T13:27:20Z</dc:date>
    </item>
    <item>
      <title>no traffic on IPS promiscuous</title>
      <link>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065492#M54454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seem like you cannot use interface names in the config and networks should be specified.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2013 14:52:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-traffic-on-ips-promiscuous/m-p/2065492#M54454</guid>
      <dc:creator>Volodymyr Morskyy</dc:creator>
      <dc:date>2013-01-02T14:52:39Z</dc:date>
    </item>
  </channel>
</rss>

