<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TCP Reset is not working in promiscuous mode for http service in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tcp-reset-is-not-working-in-promiscuous-mode-for-http-service/m-p/1627975#M65822</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured IDSM-2 in Promiscuous mode using VACLs. I have verified the configuration which is correct, IDSM-2 is capturing all the traffic from specified vlans. Issue is that when I want to block any website let suppose "facebook" for any particular user. and add the action "Reset TCP Connection" in the http service signature it does not work. The site can open by this user, although I can see the sig is triggered in the real time event (IDMS logs) and also it show the action perform against this attack but it is not resetting the TCP connection. Kindly advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aman&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:14:08 GMT</pubDate>
    <dc:creator>Shaikh Aman Uddin</dc:creator>
    <dc:date>2019-03-10T12:14:08Z</dc:date>
    <item>
      <title>TCP Reset is not working in promiscuous mode for http service</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-is-not-working-in-promiscuous-mode-for-http-service/m-p/1627975#M65822</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured IDSM-2 in Promiscuous mode using VACLs. I have verified the configuration which is correct, IDSM-2 is capturing all the traffic from specified vlans. Issue is that when I want to block any website let suppose "facebook" for any particular user. and add the action "Reset TCP Connection" in the http service signature it does not work. The site can open by this user, although I can see the sig is triggered in the real time event (IDMS logs) and also it show the action perform against this attack but it is not resetting the TCP connection. Kindly advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aman&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-is-not-working-in-promiscuous-mode-for-http-service/m-p/1627975#M65822</guid>
      <dc:creator>Shaikh Aman Uddin</dc:creator>
      <dc:date>2019-03-10T12:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Reset is not working in promiscuous mode for http servic</title>
      <link>https://community.cisco.com/t5/network-security/tcp-reset-is-not-working-in-promiscuous-mode-for-http-service/m-p/1627976#M65826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Aman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please do a SPAN capture with a source VLAN of the VLAN that the RST should go out on and see if the RST appears in the capture? If the RST does not appear in the capture, work your way back to the IPS and do a capture directly on the blade to see if the RST is egressing the IPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Blayne&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Jan 2011 00:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tcp-reset-is-not-working-in-promiscuous-mode-for-http-service/m-p/1627976#M65826</guid>
      <dc:creator>Christopher Dreier</dc:creator>
      <dc:date>2011-01-16T00:41:41Z</dc:date>
    </item>
  </channel>
</rss>

