<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network Scans in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-scans/m-p/1794924#M55990</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We actually do not own the AIP-SSM sensor module i was trying to accomplish basic ids with the ASA 5520 only...&lt;/P&gt;&lt;P&gt;to log scans to syslog etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Oct 2011 20:44:22 GMT</pubDate>
    <dc:creator>laphil</dc:creator>
    <dc:date>2011-10-24T20:44:22Z</dc:date>
    <item>
      <title>Network Scans</title>
      <link>https://community.cisco.com/t5/network-security/network-scans/m-p/1794922#M55988</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im trying to figure out how to get network scans and dos attacks to show up in my syslog server for my CIsco ASA 5520. &lt;/P&gt;&lt;P&gt;Just with the basic IPS support on the device i cannot seem to get anything to show up on my syslog server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network scans dont appear to be part of the standard IDS signatures since its just a network port scan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any direction on this would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-scans/m-p/1794922#M55988</guid>
      <dc:creator>laphil</dc:creator>
      <dc:date>2019-03-10T12:31:34Z</dc:date>
    </item>
    <item>
      <title>Network Scans</title>
      <link>https://community.cisco.com/t5/network-security/network-scans/m-p/1794923#M55989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have an AIP-SSM sensor module for your 5520?&lt;/P&gt;&lt;P&gt;If you do, then you should be able to detect network and host scanning on you network.&lt;/P&gt;&lt;P&gt;The Sensor module will not output to a syslog server, you can use the free Cisco IPS Manager Express&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/products/ps9610/index.html"&gt;http://www.cisco.com/en/US/products/ps9610/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can also set the signatures for scans to send an SNMP trap when they fire to your SNMP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 20:23:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-scans/m-p/1794923#M55989</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-10-24T20:23:53Z</dc:date>
    </item>
    <item>
      <title>Network Scans</title>
      <link>https://community.cisco.com/t5/network-security/network-scans/m-p/1794924#M55990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We actually do not own the AIP-SSM sensor module i was trying to accomplish basic ids with the ASA 5520 only...&lt;/P&gt;&lt;P&gt;to log scans to syslog etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 20:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-scans/m-p/1794924#M55990</guid>
      <dc:creator>laphil</dc:creator>
      <dc:date>2011-10-24T20:44:22Z</dc:date>
    </item>
    <item>
      <title>Network Scans</title>
      <link>https://community.cisco.com/t5/network-security/network-scans/m-p/1794925#M55991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't know of a way to directly detect scans from an ASA. I have seen some indirect scan detection performed on firewall logs in a customized SIM (Intelitactics) via correlation. &lt;/P&gt;&lt;P&gt;You may be better served asking this question in the firewall forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 21:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-scans/m-p/1794925#M55991</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-10-24T21:24:17Z</dc:date>
    </item>
  </channel>
</rss>

