<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN &amp; IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631910#M65762</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All VPN traffic is going through the IPS NME on the 2811?&lt;/P&gt;&lt;P&gt;Can you make changes to the IPS? I mean... can you shut it down for a quick test to see if the VPN traffic continue affected? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Jan 2011 21:43:56 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2011-01-26T21:43:56Z</dc:date>
    <item>
      <title>IPS Blocking VPN*</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631909#M65761</link>
      <description>&lt;P&gt;Hello readers!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a Cisco 2821 with the IPS NME module in it wich is causing problems for our VPN..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two gateways: x.x.6.1 (the router) and x.x.6.21 (software gateway)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we establish a VPN connection over x.x.6.21 everything goes fine.&lt;/P&gt;&lt;P&gt;But when we establish a VPN connection over x.x.6.1, you guessed it, it goes wrong; a connection isnt made.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After some trying out and being on the phone with Cisco Tech Support, we discovered it was the IPS getting in the .. while the IPS wasnt logging anything about stopping the packets related to the VPN connection and the IPS isnt blocking any of the IP addresses for the VPN connection.. I've also monitored it with Wireshark, when on the x.x.6.1 you see the packets with the destination address, but nothing else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been looking around but didnt find a way to solve. I hope you guys can help me out here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Moved this thread to Intrusion Prevention System/IDS because there is where it should be in the first place.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631909#M65761</guid>
      <dc:creator>m.vanwijngaarden</dc:creator>
      <dc:date>2019-03-10T12:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; IPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631910#M65762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All VPN traffic is going through the IPS NME on the 2811?&lt;/P&gt;&lt;P&gt;Can you make changes to the IPS? I mean... can you shut it down for a quick test to see if the VPN traffic continue affected? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jan 2011 21:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631910#M65762</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-26T21:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; IPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631911#M65763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Frederico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Totally forgot to mention that when I posted this. I've turned the IPS off to see if the VPN works and it did. So that also confirms that all the traffic is going through the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 07:07:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631911#M65763</guid>
      <dc:creator>m.vanwijngaarden</dc:creator>
      <dc:date>2011-01-28T07:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; IPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631912#M65764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried 2 new things:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Turned on all signatures and try to establish a VPN connection, no events logged that blocks the VPN&lt;/P&gt;&lt;P&gt;- Turned off all signatures and try to establish a VPN connection, didnt work either&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So there isnt a signature (I think) blocking the VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT, when the sensor is turned off completely, creating a VPN connection works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jan 2011 13:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631912#M65764</guid>
      <dc:creator>m.vanwijngaarden</dc:creator>
      <dc:date>2011-01-28T13:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; IPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631913#M65765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not quite familiar with the module on the router, Does it have a GUI? Can you turn on the IPS policies and try to connect again and send us the events related to the IP`s of the peers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPS cannot inspect or check VPN packets, as they come encrypted. Only in VPN termination devices, when it is decrypted and then passed on to the inside network. But that would be it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please get the events, I will help you out on this one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 04:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631913#M65765</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-01-30T04:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; IPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631914#M65766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply, Mike.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didnt give the full name of the module, its the NME-IPS-K9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also did as you asked; turn on all policies and pass through the information I'll see. When I turned on all policies and tried to make a vpn connection the following signatures fired: 1107, 1306/1 and 1306/5. BUT, these are disabled by default. So when using the normal settings, these signatures wouldnt be active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, and I use the Cisco IPS Manager Express as the GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 07:50:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631914#M65766</guid>
      <dc:creator>m.vanwijngaarden</dc:creator>
      <dc:date>2011-01-31T07:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN &amp; IPS</title>
      <link>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631915#M65767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Marco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to take a deeper look at this via a TAC case. Would you mind opening one and having it sent to the IDS team? Please forward me the SR number when you receive it so that I can pull it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Blayne Dreier&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:blayne@cisco.com"&gt;blayne@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Cisco TAC Escalation Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Please check out our Podcasts**&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TAC Security Show: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go/tacsecuritypodcast"&gt;http://www.cisco.com/go/tacsecuritypodcast&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;TAC IPS Media Series: &lt;/SPAN&gt;&lt;A class="jive-link-community-small" href="https://community.cisco.com/community/netpro/security/intrusion-prevention"&gt;https://supportforums.cisco.com/community/netpro/security/intrusion-prevention?view=tags&amp;amp;tags=tac_ips_media_series&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 16:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-blocking-vpn/m-p/1631915#M65767</guid>
      <dc:creator>Christopher Dreier</dc:creator>
      <dc:date>2011-01-31T16:58:41Z</dc:date>
    </item>
  </channel>
</rss>

