<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS system message problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755255#M56436</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tiwang.&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;Just a question: did you replace the module itself or the entire ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that I have this issue on both modules. For this reason I have to keep one shutdown :O(&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope there is another solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Dec 2011 13:44:10 GMT</pubDate>
    <dc:creator>alexpara72</dc:creator>
    <dc:date>2011-12-05T13:44:10Z</dc:date>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755249#M56430</link>
      <description>&lt;P&gt;I have IPS 4260 has the last IOS version 7.0(5)E4 and when I run diagnostic report I have the following messages &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.593 0.000 sensorApp[510] sensorApp/E transmitPacket: Error TX&amp;nbsp; Queue full, no lost buf yet16693 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.593 0.000&amp;nbsp; sensorApp[510] sensorApp/E transmitPacket: Error TX Queue full, no lost buf&amp;nbsp; yet24108 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.594 0.001 sensorApp[510] sensorApp/E&amp;nbsp; transmitPacket: Error TX Queue full, no lost buf yet39703 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011&amp;nbsp; 13:34:15.594 0.000 sensorApp[510] sensorApp/E transmitPacket: Error TX Queue&amp;nbsp; full, no lost buf yet15644 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.594 0.000 sensorApp[510]&amp;nbsp; sensorApp/E transmitPacket: Error TX Queue full, no lost buf yet38045 if =&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.595 0.001 sensorApp[510] sensorApp/E transmitPacket:&amp;nbsp; Error TX Queue full, no lost buf yet19080 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.595 0.000&amp;nbsp; sensorApp[510] sensorApp/E transmitPacket: Error TX Queue full, no lost buf&amp;nbsp; yet31928 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.595 0.000 sensorApp[510] sensorApp/E&amp;nbsp; transmitPacket: Error TX Queue full, no lost buf yet40998 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011&amp;nbsp; 13:34:15.596 0.001 sensorApp[510] sensorApp/E transmitPacket: Error TX Queue&amp;nbsp; full, no lost buf yet18245 if = 0&lt;/P&gt;&lt;P&gt;08Aug2011 13:34:15.596 0.000 sensorApp[510]&amp;nbsp; sensorApp/E transmitPacket: Error TX Queue full, no lost buf yet44343 if =&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and that's make the IPS hangging and stop working sometimes ,Does any one has solution for this problem?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755249#M56430</guid>
      <dc:creator>Michael Soliman</dc:creator>
      <dc:date>2019-03-10T12:26:57Z</dc:date>
    </item>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755250#M56431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like the IPS appliance might have been overloaded hence there is not enough buffer in the transmit Queue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a bug that contains information on what might be the issue: CSCtc18038&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtc18038"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtc18038&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 07:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755250#M56431</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-08-17T07:33:06Z</dc:date>
    </item>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755251#M56432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jennifer &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually The IPS IOS version I have is 7.0(5)E4,I believe the problem is solved in this version.&lt;/P&gt;&lt;P&gt;Please get back to me quickly as this is stopping my IPS service and I will be unable to manage the IPS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Aug 2011 07:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755251#M56432</guid>
      <dc:creator>Michael Soliman</dc:creator>
      <dc:date>2011-08-21T07:59:15Z</dc:date>
    </item>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755252#M56433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Stop the Global corrrelation update and check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Aug 2011 19:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755252#M56433</guid>
      <dc:creator>haivrajesh</dc:creator>
      <dc:date>2011-08-21T19:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755253#M56434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;I have the same problem. But I have to explain a little.&lt;/P&gt;&lt;P&gt;I have two ASA with an AIP-SSM-20 module each. The ASA are in failover configuration. Since this summer, when I begun to manage the IPS modules, I had problems with them because each module data-plane was going down after some time (about 3 days) it was up. I reset them, but they again went down on data-plan. This, obviously, caused the ASA to failover every time the primary module data-plane went down. The situation is the same nowadays.&lt;/P&gt;&lt;P&gt;This is an output from the show failover on the primary ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;slot 1: ASA-SSM-20 hw/sw rev (1.0/7.0(5a)E4) status (Up/Down)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to shutdown the IPS module on secondary ASA to not have it becoming active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking at the show tech-support on the module, I saw the lines sent on this thread at the firs post from Michael Soliman.&lt;/P&gt;&lt;P&gt;I also looked at the link sent by Jennifer, but the wos no solution in it but only a workaround.&lt;/P&gt;&lt;P&gt;The modules firmware you can see in the line above. Instead the ASA version is 8.0(5)25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other investigations I made on the Internet, I saw that some people resolved this issue having the ASA appliance substituted.&lt;/P&gt;&lt;P&gt;Is that the only way to the resolution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 12:24:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755253#M56434</guid>
      <dc:creator>alexpara72</dc:creator>
      <dc:date>2011-12-05T12:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755254#M56435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi again&lt;/P&gt;&lt;P&gt;Had a similary problem this spring - had to migrate 2 ASA5510 with SSM-10 to 2 brandnew ASA5520 with SSM-20 - while I tested the new setup - simple burn-in test running a week - there I also expirienced that after a few days I suddenly got failover because the SSM20 module failed - got a replacement and they have now been running without problems. But honestly - no idea of what was wrong with the SSM20 module - but I swapped it between the ASA's and the problem followed the SSM module&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 13:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755254#M56435</guid>
      <dc:creator>tiwang</dc:creator>
      <dc:date>2011-12-05T13:32:37Z</dc:date>
    </item>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755255#M56436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tiwang.&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;Just a question: did you replace the module itself or the entire ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is that I have this issue on both modules. For this reason I have to keep one shutdown :O(&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope there is another solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 13:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755255#M56436</guid>
      <dc:creator>alexpara72</dc:creator>
      <dc:date>2011-12-05T13:44:10Z</dc:date>
    </item>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755256#M56437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hmm - both modules? anyway - since the ssm module was part of a bundle I got the whole asa box replaced &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards /ti&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Dec 2011 13:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755256#M56437</guid>
      <dc:creator>tiwang</dc:creator>
      <dc:date>2011-12-05T13:48:59Z</dc:date>
    </item>
    <item>
      <title>IPS system message problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755257#M56438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Yes, tiwang, both modules. Anyway, I think I'm going to open a&amp;nbsp; TAC to Cisco to have the ASAs replaced because I noticed also other&amp;nbsp; issues. I don't want to get OT now, but I think those modules behave&amp;nbsp; very strangely. For example, they don't alert for a port scan I did, but&amp;nbsp; the same scan done against another ASA, in another environment, with&amp;nbsp; the SSM configured in the same way and with the same firmware, gets&amp;nbsp; logged immediately.&lt;/P&gt;&lt;P&gt;Moreover, till yesterday I had a simple config to divert traffic&amp;nbsp; to the IPS: a class map matching an acl of type ip any to any, this&amp;nbsp; class map called by the global-policy and the service policy applied&amp;nbsp; globally. In such situation the IPS logged every internal traffic (we've&amp;nbsp; many vlan on the ASA) and it was tedious going to guess the best filter&amp;nbsp; to see only what I wanted to see. So, yesterday I decided to remove the&amp;nbsp; traffic diversion from the global policy creating a new policy and&amp;nbsp; applying this only on the outside (internet) interface. The result is&amp;nbsp; that I still don't see any scan made against the firewall or the natted&amp;nbsp; services and moreover I still can see some (really, not much) packet&amp;nbsp; logged regarding internal traffic.&lt;/P&gt;&lt;P&gt;This is the current traffic diversion config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list IPS-OUTSIDE extended permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map IPS-Outside&lt;/P&gt;&lt;P&gt; match access-list IPS-OUTSIDE&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map IPS-Outside-policy&lt;/P&gt;&lt;P&gt; class IPS-Outside&lt;/P&gt;&lt;P&gt;&amp;nbsp; ips promiscuous fail-open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy IPS-Outside-policy interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, browsing the Internet, I din't find an official&amp;nbsp; announcement regarding the proplem in this topic (modules going down at&amp;nbsp; data-plane level) and an official resolution by Cisco.&lt;/P&gt;&lt;P&gt;I only found posts telling that the only resolution was the replacement of the entire ASA.&lt;/P&gt;&lt;P&gt;This is very discouraging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 09:30:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-system-message-problem/m-p/1755257#M56438</guid>
      <dc:creator>alexpara72</dc:creator>
      <dc:date>2011-12-07T09:30:25Z</dc:date>
    </item>
  </channel>
</rss>

