<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no alarm from IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583374#M65828</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA rules will be applied first before the IPS inspection because IPS is getting the traffic from the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Feb 2011 23:30:41 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-02-10T23:30:41Z</dc:date>
    <item>
      <title>no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583365#M65811</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're using AIP-SSM-40, Version 7.0(2)E4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We send traffic from all interfaces to the IPS. When we test it with sigID 2004, we don't have any alarm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;the configuration on the ASA is as follow :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_mpc extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map inside-ip-class&lt;BR /&gt; match access-list inside_mpc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;policy-map inside-ips-policy&lt;BR /&gt; class inside-ip-class&lt;BR /&gt;&amp;nbsp; ips inline fail-open&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;service-policy inside-ips-policy interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the AIP-SSM, the configuration is as follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;signatures 2004 0&lt;BR /&gt;alert-severity high&lt;BR /&gt;engine atomic-ip&lt;BR /&gt;event-action produce-alert|produce-verbose-alert|deny-attacker-inline|deny-connection-inline|deny-packet-inline&lt;BR /&gt;specify-l4-protocol yes&lt;BR /&gt;l4-protocol icmp&lt;BR /&gt;specify-icmp-type no&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;what we should do to have alarm?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:14:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583365#M65811</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2019-03-10T12:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583366#M65812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by alarm? Are you saying that you are not able to see the events that is triggered by signature# 2004?&lt;/P&gt;&lt;P&gt;Can you check what is the Alert Frequency configured for this signature? The default is "Summarize" every 30 seconds. You might want to change the Alert Frequency to "Fire All" if you are using signature#2004 to test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plus you would need to send the traffic across the ASA so traffic will be inspected by the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lastly, I am assuming that you have already enabled/assigned the IPS virtual sensor (vs0) to the signature (sig0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jan 2011 08:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583366#M65812</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-24T08:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583367#M65813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The alert frequency is "fire all" and we sent continuous ping. we also tested with other signature (FTP authentication failure) but no alarm.&lt;/P&gt;&lt;P&gt;we used default sensor on each interface. so do we need to change it into vs0 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 09:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583367#M65813</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-01-31T09:55:53Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583368#M65814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please confirm if you are sending the traffic through the ASA firewall? I would suggest that you assign the IPS as global policy on your ASA, and on the IPS itself, pls check if the virtual sensor has been enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jan 2011 15:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583368#M65814</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-01-31T15:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583369#M65815</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we sent traffic through the ASA, it is enabled on each interface, not globally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we used vs0 as you suggested, it's working.&lt;/P&gt;&lt;P&gt;Thanks indeed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the configuration is now like that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map dmz-ips-policy&lt;BR /&gt; class dmz-ips-class&lt;BR /&gt;&amp;nbsp; ips inline fail-open sensor vs0&lt;BR /&gt;policy-map outside-ips-policy&lt;BR /&gt; class outside-ips-class&lt;BR /&gt;&amp;nbsp; ips inline fail-open sensor vs0&lt;BR /&gt;policy-map inside-ips-policy&lt;BR /&gt; class inside-ips-class&lt;BR /&gt;&amp;nbsp; ips inline fail-open sensor vs0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before, we use default sensor and the configuration is as follow :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map inside-ips-policy&lt;BR /&gt; class inside-ips-class&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ips inline fail-open sensor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;didn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We used default sensor on another ASA, with other IPS version, it worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there any explanation?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2011 08:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583369#M65815</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-02-02T08:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583370#M65817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you running multiple context on the firewall, or just a single context?&lt;/P&gt;&lt;P&gt;The initial configuration that you have should work just fine, as long as you have enabled vs0 on the IPS module itself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2011 18:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583370#M65817</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-02T18:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583371#M65820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're running single context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to check on the IPS if vs0 is enabled?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 07:58:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583371#M65820</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-02-03T07:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583372#M65821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you IDM into the IPS, under Configuration --&amp;gt; Interface Configuration --&amp;gt; Summary --&amp;gt; check if under the "Assigned Virtual sensor" colum if vs0 is assigned.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Feb 2011 17:38:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583372#M65821</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-03T17:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583373#M65825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more question Jennifer, we'd like to know which is applied first, the ASA rules or IPS ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 14:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583373#M65825</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-02-10T14:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583374#M65828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA rules will be applied first before the IPS inspection because IPS is getting the traffic from the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2011 23:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583374#M65828</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-10T23:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: no alarm from IPS</title>
      <link>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583375#M65829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, thanks for all Jennifer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Feb 2011 08:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-alarm-from-ips/m-p/1583375#M65829</guid>
      <dc:creator>harinirina</dc:creator>
      <dc:date>2011-02-18T08:45:35Z</dc:date>
    </item>
  </channel>
</rss>

