<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ask : IPS Bottleneck Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956886#M55134</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please give me an understanding about the ips packet flow inspection.&lt;/P&gt;&lt;P&gt;I got a problem with IPS, it seems like a Bottleneck issue.&lt;/P&gt;&lt;P&gt;When i turning on the IPS machine, all process being down.&lt;/P&gt;&lt;P&gt;But when i turning off the IPS, all process begin normal again.&lt;/P&gt;&lt;P&gt;FYI, i already setting the by pass configuration to ON and setting whole events action Rule being "Produce Alert" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What probably cause with my problem ? &lt;/P&gt;&lt;P&gt;What should i conduct with Anomaly Detection ? Should i change the AD mode to be inactive ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:41:53 GMT</pubDate>
    <dc:creator>probopurwo</dc:creator>
    <dc:date>2019-03-10T12:41:53Z</dc:date>
    <item>
      <title>Ask : IPS Bottleneck Issue</title>
      <link>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956886#M55134</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please give me an understanding about the ips packet flow inspection.&lt;/P&gt;&lt;P&gt;I got a problem with IPS, it seems like a Bottleneck issue.&lt;/P&gt;&lt;P&gt;When i turning on the IPS machine, all process being down.&lt;/P&gt;&lt;P&gt;But when i turning off the IPS, all process begin normal again.&lt;/P&gt;&lt;P&gt;FYI, i already setting the by pass configuration to ON and setting whole events action Rule being "Produce Alert" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What probably cause with my problem ? &lt;/P&gt;&lt;P&gt;What should i conduct with Anomaly Detection ? Should i change the AD mode to be inactive ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956886#M55134</guid>
      <dc:creator>probopurwo</dc:creator>
      <dc:date>2019-03-10T12:41:53Z</dc:date>
    </item>
    <item>
      <title>Ask : IPS Bottleneck Issue</title>
      <link>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956887#M55135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by "all process being down" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With Bypass set to ON, IPS should simply pass all traffic without analyzing.&lt;/P&gt;&lt;P&gt;Event Action being set to "Produce Alert", is the alert rate too high ? Are there some particular signatures firing a lot ? (Check show statistics virtual-sensor).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jun 2012 01:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956887#M55135</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-06-10T01:18:53Z</dc:date>
    </item>
    <item>
      <title>Ask : IPS Bottleneck Issue</title>
      <link>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956888#M55136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank Sawan for your answer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;first i want to inform you about the all process being down, it mean that the server inside the server farm being down when i turn on the IPS.&lt;/P&gt;&lt;P&gt;i already set the by pass ON in interface, and make all action in signatures to be produce alert, mean that no packet drop / modify inline conducted by the IPS Sensor, but the servers still cannot operate as well as IPS being turning off.&lt;/P&gt;&lt;P&gt;what problem may be occure ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2012 02:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956888#M55136</guid>
      <dc:creator>probopurwo</dc:creator>
      <dc:date>2012-06-11T02:08:17Z</dc:date>
    </item>
    <item>
      <title>Ask : IPS Bottleneck Issue</title>
      <link>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956889#M55137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If Bypass is set to ON, then IPS shouldn't be doing anything. It looks like a configuration issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2012 15:00:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956889#M55137</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-06-11T15:00:35Z</dc:date>
    </item>
    <item>
      <title>Ask : IPS Bottleneck Issue</title>
      <link>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956890#M55138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, it should be like that, but actually when i setting up the by pass to be ON, the traffic from server farm still can operate as well as turning off IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;actually, i just configure the interface pair, one to ASA and one to Access-Server Farm.&lt;/P&gt;&lt;P&gt;before, this configuration can operate well, and no problem occure.&lt;/P&gt;&lt;P&gt;but after deploying some Application inside the Server Farm, there are so many problem, most of them is The Process of the Application being "Slow" When the IPS is turning ON.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best practice configuration of IPS, what do you think ? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 02:05:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-ips-bottleneck-issue/m-p/1956890#M55138</guid>
      <dc:creator>probopurwo</dc:creator>
      <dc:date>2012-06-12T02:05:25Z</dc:date>
    </item>
  </channel>
</rss>

