<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Signature 1330 causes packet drops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635321#M65564</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sid,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer. I learned that most of packets where the Signature 1330 triggers are packets from the IPS module to the IPS Express Manager. I added wireshark dump to the case.&lt;/P&gt;&lt;P&gt;That's really odd, i ran a traceroute from the IPS Manager to the IPS Module and vice versa and the flow look ok to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trace from the IPS module to the IPS Manager&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# trace 10.0.128.5&lt;BR /&gt;traceroute to 10.0.128.5 (10.0.128.5), 4 hops max, 40 byte packets&lt;BR /&gt; 1&amp;nbsp; 172.16.1.9 (172.16.1.9)&amp;nbsp; 1.479 ms&amp;nbsp; 1.327 ms&amp;nbsp; 1.275 ms&lt;BR /&gt; 2&amp;nbsp; 172.16.1.1 (172.16.1.1)&amp;nbsp; 3.616 ms&amp;nbsp; 2.952 ms&amp;nbsp; 1.907 ms&lt;BR /&gt; 3&amp;nbsp; 10.89.27.10 (10.89.27.10)&amp;nbsp; 2.288 ms&amp;nbsp; 2.044 ms&amp;nbsp; 2.136 ms&lt;BR /&gt; 4&amp;nbsp; 10.89.27.21 (10.89.27.21)&amp;nbsp; 8.106 ms&amp;nbsp; 9.148 ms&amp;nbsp; 8.266 ms&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;return path&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; C:\Users\Administrator.NOS-POC&amp;gt;tracert 172.16.1.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tracing route to 172.16.1.11 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp; 10.0.128.1&lt;BR /&gt;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp; 172.16.2.1&lt;BR /&gt;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.89.27.22&lt;BR /&gt;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp; 10.89.27.9&lt;BR /&gt;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp; 172.16.1.6&lt;BR /&gt;&amp;nbsp; 6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp; 172.16.1.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;trace from the IPS module's gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#traceroute vrf CENTRAL 10.0.128.5 source 172.16.1.9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 10.0.128.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 172.16.1.1 0 msec 0 msec 0 msec&lt;BR /&gt;&amp;nbsp; 2 10.89.27.10 0 msec 0 msec 4 msec&lt;BR /&gt;&amp;nbsp; 3 10.89.27.21 8 msec 8 msec 8 msec&lt;BR /&gt;&amp;nbsp; 4 172.16.2.6 8 msec 8 msec 4 msec&lt;BR /&gt;&amp;nbsp; 5 10.0.128.5 4 msec 4 msec 4 msec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what make me wonder is that the IPS module doesn't show hops further than 4 hops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Feb 2011 11:53:01 GMT</pubDate>
    <dc:creator>alex.dersch</dc:creator>
    <dc:date>2011-02-27T11:53:01Z</dc:date>
    <item>
      <title>Signature 1330 causes packet drops</title>
      <link>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635319#M65562</link>
      <description>&lt;P&gt;Hello Members,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i see in my IPS-NME module a hign number of packet drops because of the following signatures:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1330-17: TCP segment out of state order&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1330-12: TCP segment is out of order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the targets and the attacers are internal hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are these signatures triggered because of not propper configured policies or is this an indicator for problems in the internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your inputs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635319#M65562</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2019-03-10T12:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Signature 1330 causes packet drops</title>
      <link>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635320#M65563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All signatures in the 1330 range belong to the Normaliser Engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A. So in nutshell below are is a brief description of IP Fragment and TCP normalisation and why we use in the IPS:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html#wp1014834"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_signature_engines.html#wp1014834&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;B. If you are seeing 1330-17 or 1330-12 it means there might asymmetrical traffic flow in the network.&lt;/P&gt;&lt;P&gt;Or maybe the virtual sensor is not seeing both sides of the TCP connection and only seeing half connection.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Examples of this is traffic coming into the IPS via a interface assigned to virtual sensor A.&lt;/P&gt;&lt;P&gt;The return traffic enters the IPS via interface which is assigned to virtual sensor B.&lt;/P&gt;&lt;P&gt;So both virtual sensors only see half connection each, causing the normaliser signatures to fire.&lt;/P&gt;&lt;P&gt;So the normaliser signatures firing is a function of how traffic is flowing through your network, or how the IPS is seeing it at the virtual sensor level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C. You can put the IPS in assymetrical mode and see it makes a difference.&lt;/P&gt;&lt;P&gt;Different modes and description:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_virtual_sensors.html#wp1034136"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_virtual_sensors.html#wp1034136&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopt this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Feb 2011 22:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635320#M65563</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-02-26T22:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Signature 1330 causes packet drops</title>
      <link>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635321#M65564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sid,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer. I learned that most of packets where the Signature 1330 triggers are packets from the IPS module to the IPS Express Manager. I added wireshark dump to the case.&lt;/P&gt;&lt;P&gt;That's really odd, i ran a traceroute from the IPS Manager to the IPS Module and vice versa and the flow look ok to me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trace from the IPS module to the IPS Manager&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;# trace 10.0.128.5&lt;BR /&gt;traceroute to 10.0.128.5 (10.0.128.5), 4 hops max, 40 byte packets&lt;BR /&gt; 1&amp;nbsp; 172.16.1.9 (172.16.1.9)&amp;nbsp; 1.479 ms&amp;nbsp; 1.327 ms&amp;nbsp; 1.275 ms&lt;BR /&gt; 2&amp;nbsp; 172.16.1.1 (172.16.1.1)&amp;nbsp; 3.616 ms&amp;nbsp; 2.952 ms&amp;nbsp; 1.907 ms&lt;BR /&gt; 3&amp;nbsp; 10.89.27.10 (10.89.27.10)&amp;nbsp; 2.288 ms&amp;nbsp; 2.044 ms&amp;nbsp; 2.136 ms&lt;BR /&gt; 4&amp;nbsp; 10.89.27.21 (10.89.27.21)&amp;nbsp; 8.106 ms&amp;nbsp; 9.148 ms&amp;nbsp; 8.266 ms&lt;BR /&gt;#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;return path&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; C:\Users\Administrator.NOS-POC&amp;gt;tracert 172.16.1.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tracing route to 172.16.1.11 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp; 10.0.128.1&lt;BR /&gt;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 ms&amp;nbsp; 172.16.2.1&lt;BR /&gt;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 ms&amp;nbsp; 10.89.27.22&lt;BR /&gt;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9 ms&amp;nbsp; 10.89.27.9&lt;BR /&gt;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp; 172.16.1.6&lt;BR /&gt;&amp;nbsp; 6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8 ms&amp;nbsp; 172.16.1.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;trace from the IPS module's gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#traceroute vrf CENTRAL 10.0.128.5 source 172.16.1.9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 10.0.128.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 172.16.1.1 0 msec 0 msec 0 msec&lt;BR /&gt;&amp;nbsp; 2 10.89.27.10 0 msec 0 msec 4 msec&lt;BR /&gt;&amp;nbsp; 3 10.89.27.21 8 msec 8 msec 8 msec&lt;BR /&gt;&amp;nbsp; 4 172.16.2.6 8 msec 8 msec 4 msec&lt;BR /&gt;&amp;nbsp; 5 10.0.128.5 4 msec 4 msec 4 msec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what make me wonder is that the IPS module doesn't show hops further than 4 hops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Feb 2011 11:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-1330-causes-packet-drops/m-p/1635321#M65564</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2011-02-27T11:53:01Z</dc:date>
    </item>
  </channel>
</rss>

