<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic deactivated signatures still causing drops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771937#M56124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no, but all traffic from the subnets that the issue is on are specifically excluded from the IPS signature list with custom signatures. ( its an issue that requires a lowerd MTU to fix, but causes fragmenting at certain times )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the IPS modules STILL fire even on traffic excluded if the signatures match the traffic? How is the traffic to be excluded other than retiring the whole signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Oct 2011 00:22:55 GMT</pubDate>
    <dc:creator>daniel.thompson</dc:creator>
    <dc:date>2011-10-17T00:22:55Z</dc:date>
    <item>
      <title>deactivated signatures still causing drops</title>
      <link>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771935#M56118</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a site with 2x 5540 asas with SSM-20 IPS Module in active standby mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The signatures 1204 and 1208 relating to Fragmented IP datagrams fire on traffic even when excluded from the siganture set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why and how to fix this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;error attach as a pic&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771935#M56118</guid>
      <dc:creator>daniel.thompson</dc:creator>
      <dc:date>2019-03-10T12:30:26Z</dc:date>
    </item>
    <item>
      <title>deactivated signatures still causing drops</title>
      <link>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771936#M56120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have these signatures been retired and disabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick Smith&lt;/P&gt;&lt;P&gt;Cisco IPS Signature Team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 20:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771936#M56120</guid>
      <dc:creator>nicksmi</dc:creator>
      <dc:date>2011-10-14T20:01:08Z</dc:date>
    </item>
    <item>
      <title>deactivated signatures still causing drops</title>
      <link>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771937#M56124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no, but all traffic from the subnets that the issue is on are specifically excluded from the IPS signature list with custom signatures. ( its an issue that requires a lowerd MTU to fix, but causes fragmenting at certain times )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will the IPS modules STILL fire even on traffic excluded if the signatures match the traffic? How is the traffic to be excluded other than retiring the whole signature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Oct 2011 00:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771937#M56124</guid>
      <dc:creator>daniel.thompson</dc:creator>
      <dc:date>2011-10-17T00:22:55Z</dc:date>
    </item>
    <item>
      <title>deactivated signatures still causing drops</title>
      <link>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771938#M56128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From a colleague,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to prevent these two sigs (1204 and 1208) from firing is to retire them and then reset the sensor.&amp;nbsp; Disabling them will only stop alerting, and they will continue to deny packets (this is part of the normalizer’s design).&amp;nbsp; I don’t think a custom sig will work because the normalizer sigs will be processed before the custom sigs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Sig 1204 is ‘IP Fragment Missing Initial Fragment’&lt;/P&gt;&lt;P&gt; And 1208 is ‘IP Fragment Incomplete Datagram’&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; There’s not much we can do with sig 1204.&amp;nbsp; If the initial fragment is missing, we can’t do reassembly.&lt;/P&gt;&lt;P&gt; However, with sig 1208, we can adjust the timeout, which defaults to 60 seconds.&amp;nbsp; Sixty seconds should be plenty of time though.&amp;nbsp;&amp;nbsp; It can be increased to up to 360 seconds by modifying fragment-reassembly-timeout.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the dropped frags causing network issues?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Oct 2011 20:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deactivated-signatures-still-causing-drops/m-p/1771938#M56128</guid>
      <dc:creator>nicksmi</dc:creator>
      <dc:date>2011-10-17T20:28:13Z</dc:date>
    </item>
  </channel>
</rss>

