<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS blocking most web sites in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-blocking-most-web-sites/m-p/1763442#M56308</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Andrew -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your AIP-SSM module is really in promiscious mode, it shouldn't be blocking ANY traffic. Did you enable shunning on the sensor? (that would pop a blocking ACL in the ASA for 30 min or so per event). &lt;/P&gt;&lt;P&gt;Where are you seeing the packets denied?&lt;/P&gt;&lt;P&gt;If you remove the IDS configuration from your ASA does your web blocking problem stop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Sep 2011 19:13:41 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2011-09-08T19:13:41Z</dc:date>
    <item>
      <title>IPS blocking most web sites</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-most-web-sites/m-p/1763441#M56307</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have installed an SSM module in a 5510 firewall, and am running IPS in promiscous mode.&amp;nbsp; Using the default configuration i can see lots of packets being denied, and when i tested it in inline mode almost all the websites i tried to connect to didn't work including Cisco.com.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;google.com, and gmail both worked, Cisco.com only loaded half a page, microsoft.com, bbc.co.uk, telegraaf.nl, and sportinglife failed to load.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My first question is did i do something wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is it so restrictive, this doesn't meet the balance between security and productivity?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a suggested configuration that i can download, or do i need to go through each alert and assess the security risk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device is running 7.0(5a)E4S589.0 signature 589.0&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-most-web-sites/m-p/1763441#M56307</guid>
      <dc:creator>andrewjballard</dc:creator>
      <dc:date>2019-03-10T12:28:12Z</dc:date>
    </item>
    <item>
      <title>IPS blocking most web sites</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-most-web-sites/m-p/1763442#M56308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Andrew -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your AIP-SSM module is really in promiscious mode, it shouldn't be blocking ANY traffic. Did you enable shunning on the sensor? (that would pop a blocking ACL in the ASA for 30 min or so per event). &lt;/P&gt;&lt;P&gt;Where are you seeing the packets denied?&lt;/P&gt;&lt;P&gt;If you remove the IDS configuration from your ASA does your web blocking problem stop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 19:13:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-most-web-sites/m-p/1763442#M56308</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-09-08T19:13:41Z</dc:date>
    </item>
  </channel>
</rss>

