<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS don't see any traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675244#M65001</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check on the IPS itself that you have enabled the Virtual Sensor. It is not enabled by default, and you have to enable it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Jun 2011 07:19:06 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-06-20T07:19:06Z</dc:date>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675243#M65000</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I’ve configured IPS module in Cisco ASA firewall, unfortunately for unknown reason, I can’t see any network traffic hit the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the number of packet is increase by issuing “show interface” command, but there is no traffic hit the IPS when I issue “show statistics analysis-engine” command. &lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;IPS-A# sh int gigabitEthernet0/1 | i Total Packets Received&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Total Packets Received = 107449498&lt;/P&gt;&lt;P&gt;IPS-A# sh int gigabitEthernet0/1 | i Total Packets Received&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Total Packets Received = 107449511&lt;/P&gt;&lt;/PRE&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;IPS-A# sh stat analysis-engine &lt;BR /&gt;Analysis Engine Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Number of seconds since service started = 13836300&lt;BR /&gt;&amp;nbsp;&amp;nbsp; The rate of TCP connections tracked per second = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; The rate of packets per second = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; The rate of bytes per second = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Receiver Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total number of packets processed since reset = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total number of IP packets processed since reset = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Transmitter Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total number of packets transmitted = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total number of packets denied = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total number of packets reset = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Fragment Reassembly Unit Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of fragments currently in FRU = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of datagrams currently in FRU = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; TCP Stream Reassembly Unit Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP streams currently in the embryonic state = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP streams currently in the established state = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP streams currently in the closing state = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP streams currently in the system = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP Packets currently queued for reassembly = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; The Signature Database Statistics.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total nodes active = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP nodes keyed on both IP addresses and both ports = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP nodes keyed on both IP addresses and both ports = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP nodes keyed on both IP addresses = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Statistics for Signature Events&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of SigEvents since reset = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Statistics for Actions executed on a SigEvent&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Alerts written to the IdsEventStore = 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Inspection Stats&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you need to know more info.&lt;/P&gt;&lt;P&gt;Any advise would be appreciated, thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:22:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675243#M65000</guid>
      <dc:creator>Adam David</dc:creator>
      <dc:date>2019-03-10T12:22:53Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675244#M65001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check on the IPS itself that you have enabled the Virtual Sensor. It is not enabled by default, and you have to enable it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 07:19:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675244#M65001</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-20T07:19:06Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675245#M65002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jennifer for your prompt reply. I've checked on CSM &amp;gt; Virtual Sensors and found that it already has been assigned to GigabitEthernet0/1 interface. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 09:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675245#M65002</guid>
      <dc:creator>Adam David</dc:creator>
      <dc:date>2011-06-20T09:11:42Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675246#M65003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you also check if under Interface Configuration --&amp;gt; Interfaces --&amp;gt; GigabitEthernet0/1 has also been enabled as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2011 12:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675246#M65003</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-20T12:04:16Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675247#M65004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've checked both and confirmed that GigabitEthernet0/1 has been assigned to the IPS. Attached is the screenshot for your reference. Is there anything else I can do to fix this? Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Interfaces&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/6/1/50161-IPS%20-%20Interfaces.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Virtual Sensors&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/6/1/50160-IPS%20-%20Virtual%20Sensors.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 03:56:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675247#M65004</guid>
      <dc:creator>Adam David</dc:creator>
      <dc:date>2011-06-21T03:56:36Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675248#M65005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, that looks like it has been correctly configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please share a copy of "show run" from the ASA, and also "show tech" from the AIP module. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 05:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675248#M65005</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-06-21T05:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675249#M65006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;I've checked both and confirmed that GigabitEthernet0/1 has been assigned to the IPS. Attached is the screenshot for your reference. Is there anything else I can do to fix this?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;After making this change in CSM, have you submitted and deployed it to the sensor? If not, go ahead and &lt;EM&gt;Submit and Deploy&lt;/EM&gt;, then confirm whether the issue remains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Jennifer noted, a '&lt;SPAN style="font-family: courier new,courier;"&gt;show tech&lt;/SPAN&gt;' command output from the sensor can help confirm this (it will include a '&lt;SPAN style="font-family: courier new,courier;"&gt;show stat virtual&lt;/SPAN&gt;' command output which will indicate if the sensing interface is in-fact assigned on the live sensor).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, is this AIP-SSM sensor module installed in a standalone ASA or an Active/Standby failover pair? If the latter, then you'll want to ensure that you are working on the module installed in the Active ASA (the AIP-SSM sensor modules do not currently replicate/synchronize their configuration like the ASAs do, and must each be configured).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2011 13:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675249#M65006</guid>
      <dc:creator>Dustin Ralich</dc:creator>
      <dc:date>2011-06-21T13:32:46Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675250#M65007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jenifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ssc-5 in an asa 5505 and looks like its not assigned the default sensor.&amp;nbsp; can you please tell me where I change this please&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2011 13:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675250#M65007</guid>
      <dc:creator>agent2007</dc:creator>
      <dc:date>2011-06-29T13:41:14Z</dc:date>
    </item>
    <item>
      <title>IPS don't see any traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675251#M65008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its OK I got it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jun 2011 13:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-don-t-see-any-traffic/m-p/1675251#M65008</guid>
      <dc:creator>agent2007</dc:creator>
      <dc:date>2011-06-29T13:51:09Z</dc:date>
    </item>
  </channel>
</rss>

