<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I test my IPS? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970045#M55171</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create a custom signature (engine string TCP), and specify telnet port, and configure regex. When it detected the regex settings that you specify, it will trigger the signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 May 2012 12:58:08 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-05-29T12:58:08Z</dc:date>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970039#M55162</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 5520 ASA's in Active/standby mode, they both have the AIP-10 modules installed with 7.0(6).E4 installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I test it is all working can I fire any test scripts through the ASA to trigger an alert and se that it gets blocked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also how do I keep these to IPS modules in sync?&amp;nbsp; I have to mak changes on one then the other all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970039#M55162</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2019-03-10T12:41:31Z</dc:date>
    </item>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970040#M55164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To test the IPS functionality, you can enable signature# 2000 (echo-reply) and 2004 (echo-request) and ping across the ASA. You should get those 2 triggered as a test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the IPS modules in ASA active/standby mode, unfortunately the configuration will not be sync automatically and there is a bit of manual work involved to get the config synchronized. The IPS modules are standalone unfortunately.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 01:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970040#M55164</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-29T01:40:41Z</dc:date>
    </item>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970041#M55165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also make sure the signatures 2000 and 2004 are un retired besides enabling them. In recent versions they have been retired. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;qssp-8083(config-sig-sig)# stat&lt;/P&gt;&lt;P&gt;qssp-8083(config-sig-sig-sta)# sh set&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; status&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; -----------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enabled: false &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; retired: true &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 02:23:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970041#M55165</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2012-05-29T02:23:54Z</dc:date>
    </item>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970042#M55167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; We can't use teh echo one for testing as we have soem important monitoring servers that will have issues, is there any other way we can test if the IPS modules are blocking?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 08:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970042#M55167</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2012-05-29T08:57:22Z</dc:date>
    </item>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970043#M55169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create custom signature and block for example telnet traffic going through the ASA. You just have to specify the TCP port within the custom signature. Or you can configure any other ports for testing purposes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 11:36:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970043#M55169</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-29T11:36:29Z</dc:date>
    </item>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970044#M55170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; To create a custom rule for Telnet can I use the Cisco IPS ME?&amp;nbsp; I woudl like to block 192.168.9.11 from telnetting to 172.30.1.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 12:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970044#M55170</guid>
      <dc:creator>Andy White</dc:creator>
      <dc:date>2012-05-29T12:23:58Z</dc:date>
    </item>
    <item>
      <title>How can I test my IPS?</title>
      <link>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970045#M55171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create a custom signature (engine string TCP), and specify telnet port, and configure regex. When it detected the regex settings that you specify, it will trigger the signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 12:58:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-can-i-test-my-ips/m-p/1970045#M55171</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-05-29T12:58:08Z</dc:date>
    </item>
  </channel>
</rss>

