<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What traffic gets copied to IPS Module?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948508#M55443</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Mar 2012 14:31:13 GMT</pubDate>
    <dc:creator>sawgupta</dc:creator>
    <dc:date>2012-03-23T14:31:13Z</dc:date>
    <item>
      <title>What traffic gets copied to IPS Module??</title>
      <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948503#M55429</link>
      <description>&lt;P&gt;We have an ASA5585-X with SSP-10 module installed that we are testing. The firewall's outside interface is connected to the internet and has a public address. We have CSM 4.2 installed and are sending events from the IPS to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After we configured the IPS module we expected to get lots of alerts for attacks originating from the internet, but we hardly see anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACL that we have on the outside interface doesn't actually allow much in, just some SMTP, HTTP, DNS, SSH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is this - should the IPS see all traffic/attacks coming from the internet, or JUST packets that have passed the outside ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suspect this is why we are seeing very few alerts - can anyone confirm this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//\/\\\&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:38:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948503#M55429</guid>
      <dc:creator>mattleayr</dc:creator>
      <dc:date>2019-03-10T12:38:37Z</dc:date>
    </item>
    <item>
      <title>What traffic gets copied to IPS Module??</title>
      <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948504#M55430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; The traffic does not automatically get copied to the IPS, you need to create an access-list and class-map to apply (like QoS)&lt;/P&gt;&lt;P&gt;access-list IPS extended permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map global-ips&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; match access-list IPS&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; class global-ips&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ips inline fail-open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;Internally the traffic is passed from the firewall to the IPS module through an internal interface (port channel on the 5585's) at the last step just prior to the traffic exiting the firewall. This is why the IPS modules do not have a "normalizer" engine, this is already performed by the ASA prior to inspection, the ASA normalizer is essentially the same as what is found on IPS. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2012 22:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948504#M55430</guid>
      <dc:creator>jhampt20_ford</dc:creator>
      <dc:date>2012-03-22T22:18:47Z</dc:date>
    </item>
    <item>
      <title>What traffic gets copied to IPS Module??</title>
      <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948505#M55432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm aware of that - we have the policy map configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're getting very few alerts from IPS - I was expecting more, as the outside interface has a public IP address and there are scans, probes etc happening all the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me put my question a different way - does the IPS module ever see traffic that is DROPPED by the outside interface ACL??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 12:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948505#M55432</guid>
      <dc:creator>mattleayr</dc:creator>
      <dc:date>2012-03-23T12:17:45Z</dc:date>
    </item>
    <item>
      <title>What traffic gets copied to IPS Module??</title>
      <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948506#M55435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the traffic has been dropped by ASA, then IPS won't have any visibility to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 13:03:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948506#M55435</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-03-23T13:03:17Z</dc:date>
    </item>
    <item>
      <title>What traffic gets copied to IPS Module??</title>
      <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948507#M55442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if there was a DOS attack occurring on the outside interface (possibly saturating our internet link) and the DOS traffic was being dropped by the ACL, IPS would have no visibility of that??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 14:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948507#M55442</guid>
      <dc:creator>mattleayr</dc:creator>
      <dc:date>2012-03-23T14:26:59Z</dc:date>
    </item>
    <item>
      <title>What traffic gets copied to IPS Module??</title>
      <link>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948508#M55443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2012 14:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-traffic-gets-copied-to-ips-module/m-p/1948508#M55443</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-03-23T14:31:13Z</dc:date>
    </item>
  </channel>
</rss>

