<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL block entries are not added in 6500 IOS switch by IPS AR in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805195#M56138</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bob, it's already done.&lt;/P&gt;&lt;P&gt;-the 6500 is configured as IOS&amp;nbsp; block device&lt;/P&gt;&lt;P&gt;-there are signatures with block host&amp;nbsp; event rules &lt;/P&gt;&lt;P&gt;-there are blocked hosts in the IPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just discovered that&amp;nbsp; there are errors&amp;nbsp; in the log&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ips4260-1# sh events error | include : nac&lt;/P&gt;&lt;P&gt;evError: eventId=1317178506899167905 severity=error vendor=Cisco&lt;BR /&gt;originator:&lt;BR /&gt;hostId: ips4260-1&lt;BR /&gt;appName: nac&lt;BR /&gt;appInstanceId: 28636&lt;BR /&gt;time: 2011/10/06 08:19:10 2011/10/06 09:14:10 EST&lt;BR /&gt;errorMessage: name=errSystemError Established a connection to IP [10.1.1.100]&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that the problem is connected to the fact that the 6500 config is quite big ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Oct 2011 08:41:25 GMT</pubDate>
    <dc:creator>vlad_ezh</dc:creator>
    <dc:date>2011-10-06T08:41:25Z</dc:date>
    <item>
      <title>ACL block entries are not added in 6500 IOS switch by IPS ARC</title>
      <link>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805193#M56136</link>
      <description>&lt;P&gt;The situation is the following:&lt;/P&gt;&lt;P&gt;IPS device - IPS4260&amp;nbsp; 7.0(6)E4&lt;/P&gt;&lt;P&gt;ARC device - 6500 IOS 12.2(33)SXI5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500 has 2 Internet connections -&amp;nbsp; vlan2 and vlan11&amp;nbsp; are according L3 interfaces.&lt;/P&gt;&lt;P&gt;IPS works in promiscious mode, traffic captured using VACL capture&amp;nbsp; on vlan2 and vlan11.&lt;/P&gt;&lt;P&gt;the servers which must be protected are in vlan 8, i need to setup outgoing block ACL on Vlan8 L3 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two problems wiht this configurtion:&lt;/P&gt;&lt;P&gt;1)IPS didnot enter blocked hosts and connections into the ACL.&amp;nbsp; I see that the ACL on intreface is regualrly changed from IDS_Vlan8_out_1 to IDS_Vlan8_out_0, but no block entries are added .&lt;/P&gt;&lt;P&gt;2)if I to try read&amp;nbsp; running config i regularly got&amp;nbsp; the warning that the configration is not accesible. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How often the&amp;nbsp; IPS shoudl change the block ACls?&lt;/P&gt;&lt;P&gt;Why it doesn't add the Block entries?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any clue&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805193#M56136</guid>
      <dc:creator>vlad_ezh</dc:creator>
      <dc:date>2019-03-10T12:30:08Z</dc:date>
    </item>
    <item>
      <title>ACL block entries are not added in 6500 IOS switch by IPS ARC</title>
      <link>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805194#M56137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to specify the 6500 as a "router" device in your IPS Sensor.&lt;/P&gt;&lt;P&gt;The IPS will change the ACL in your 6500 twice for each signature that has the action set to "Request Block" that fires.&lt;/P&gt;&lt;P&gt;The first ACL change will block the host IP address, then 15 min later the host will be unblocked (it may be 30 min, I forget exactly). The function of the two ACLs is so that the sensor can have a "scratch" ACL to write then swap it out with the applied ACL.&lt;/P&gt;&lt;P&gt;To see an entry in your ACL you need to either have an existing signature set to block fire, or edit a signature to block and then hit that signature. (a custom TCP sig with a known text string works nicely).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 18:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805194#M56137</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-10-05T18:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACL block entries are not added in 6500 IOS switch by IPS AR</title>
      <link>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805195#M56138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bob, it's already done.&lt;/P&gt;&lt;P&gt;-the 6500 is configured as IOS&amp;nbsp; block device&lt;/P&gt;&lt;P&gt;-there are signatures with block host&amp;nbsp; event rules &lt;/P&gt;&lt;P&gt;-there are blocked hosts in the IPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just discovered that&amp;nbsp; there are errors&amp;nbsp; in the log&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ips4260-1# sh events error | include : nac&lt;/P&gt;&lt;P&gt;evError: eventId=1317178506899167905 severity=error vendor=Cisco&lt;BR /&gt;originator:&lt;BR /&gt;hostId: ips4260-1&lt;BR /&gt;appName: nac&lt;BR /&gt;appInstanceId: 28636&lt;BR /&gt;time: 2011/10/06 08:19:10 2011/10/06 09:14:10 EST&lt;BR /&gt;errorMessage: name=errSystemError Established a connection to IP [10.1.1.100]&lt;/P&gt;&lt;P&gt;---------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that the problem is connected to the fact that the 6500 config is quite big ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 08:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805195#M56138</guid>
      <dc:creator>vlad_ezh</dc:creator>
      <dc:date>2011-10-06T08:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: ACL block entries are not added in 6500 IOS switch by IPS AR</title>
      <link>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805196#M56139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Acording to your error log, the IPS sensor is not logging into the 6500 sucessfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to add the 6500's ssh key into your IPS sensor (at the command prompt)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ssh host-key 10.1.1.100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to define the 6500 and how you will talk to it (I think you've done this, in the configuration):&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;router-devices 10.1.1.100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;communication ssh&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And you need to set shunning in the config:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;conf t&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service network-access&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;general&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;block-enable true&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;user-profiles 6500&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;username cisco&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(config-net-use)# password&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Enter password[]: *********&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Re-enter password: *********&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;config-net-use)# enable-password&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Enter enable-password[]: *********&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Re-enter enable-password: *********&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[yes]&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;conf t&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;service network-access&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;general&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;block-enable true&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;router-devices 10.1.1.100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;communication SSH-3des&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;profile-name 6500&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;block-interfaces vlan8 out &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;[yes]&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 20:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805196#M56139</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-10-06T20:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACL block entries are not added in 6500 IOS switch by IPS AR</title>
      <link>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805197#M56140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It's all already done - i have tested using telnet and SSH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that&amp;nbsp; IPS sucesfully connects to 6513 as the ACLapplied to Vlan8&amp;nbsp; is continiously changed between&lt;/P&gt;&lt;P&gt;interface Vlan8&lt;/P&gt;&lt;P&gt;ip access-group IDS_Vlan8_out_0 out&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; and &lt;/P&gt;&lt;P&gt;interface Vlan8&lt;/P&gt;&lt;P&gt;ip access-group IDS_Vlan8_out_1 out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the error&amp;nbsp; :&lt;/P&gt;&lt;P&gt;------------------------------------&lt;/P&gt;&lt;P&gt;evError: eventId=1317178506899193520 severity=error vendor=Cisco&lt;BR /&gt;&amp;nbsp; originator:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: ips4260-1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: nac&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 26677&lt;BR /&gt;&amp;nbsp; time: 2011/10/07 09:40:51 2011/10/07 10:35:51 EST&lt;BR /&gt;&amp;nbsp; errorMessage: name=errSystemError Established a connection to IP [10.1.1.100]&lt;/P&gt;&lt;P&gt;-------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;looks like informing normal conenction&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried&amp;nbsp; to use incorrect passwords and gor differnt errors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------&lt;/P&gt;&lt;P&gt;evError: eventId=1317178506899193550 severity=error vendor=Cisco&lt;/P&gt;&lt;P&gt;&amp;nbsp; originator:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: ips4260-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: nac&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 27022&lt;/P&gt;&lt;P&gt;&amp;nbsp; time: 2011/10/07 09:43:10 2011/10/07 10:38:10 EST&lt;/P&gt;&lt;P&gt;&amp;nbsp; errorMessage: name=errSystemError ERROR: Wrong username/password for net device [10.1.1.100]&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;evError: eventId=1317178506899193691 severity=error vendor=Cisco&lt;BR /&gt;&amp;nbsp; originator:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostId: ips4260-1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appName: nac&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appInstanceId: 27485&lt;BR /&gt;&amp;nbsp; time: 2011/10/07 09:48:13 2011/10/07 10:43:13 EST&lt;BR /&gt;&amp;nbsp; errorMessage: name=errSystemError Bad enable password for device [10.1.1.100]&lt;/P&gt;&lt;P&gt;-------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Oct 2011 09:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-block-entries-are-not-added-in-6500-ios-switch-by-ips-arc/m-p/1805197#M56140</guid>
      <dc:creator>vlad_ezh</dc:creator>
      <dc:date>2011-10-07T09:52:10Z</dc:date>
    </item>
  </channel>
</rss>

