<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDSM handling IP Spoofing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569435#M66035</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello szekahungdanny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This would require the IDSM-2 to maintain a table of IP/MAC correlation. This is not a function of the IDSM. What you are looking for is the ip source guard feature of the Catalyst switches: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/ipsrcgrd.html"&gt;http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/ipsrcgrd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if I can help you with anything further within the context of this thread. If your question has been Answered, please mark the thread as such so that it will be helpful to other users. Also, please feel free to Rate this thread to reflect your experience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Blayne Dreier&lt;BR /&gt;Cisco TAC Escalation Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Please check out our Podcasts**&lt;BR /&gt;&lt;SPAN&gt;TAC Security Show: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go/tacsecuritypodcast"&gt;http://www.cisco.com/go/tacsecuritypodcast&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;TAC IPS Media Series: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12758"&gt;https://supportforums.cisco.com/docs/DOC-12758&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Feb 2011 19:44:49 GMT</pubDate>
    <dc:creator>Christopher Dreier</dc:creator>
    <dc:date>2011-02-07T19:44:49Z</dc:date>
    <item>
      <title>IDSM handling IP Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569432#M66032</link>
      <description>&lt;P&gt;anyone know IDSM could detect IP Spoofing ?&lt;/P&gt;&lt;P&gt;currently, we have set mirroring entire vlan traffic into IDSM. All workstations under same VLAN.&lt;/P&gt;&lt;P&gt;Within the VLAN, always having duplicated IP happened. and we concern is it IP spoffing happened on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to simulate the situation...We set 2 workstaions with same IPs but different MAC addresses.&lt;/P&gt;&lt;P&gt;Normally, pc would get duplicated IP address conflict. Would IDSM could sense this? However, I fail to get any event for this in IDSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestion to simulate the situation? and did IDSM support detecting IP Spoofing?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569432#M66032</guid>
      <dc:creator>szekahungdanny</dc:creator>
      <dc:date>2019-03-10T12:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM handling IP Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569433#M66033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest moving this question over to the IPS/IDS community, the experts there will have a better answer for you:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-community-small" href="https://community.cisco.com/community/netpro/security/intrusion-prevention"&gt;https://supportforums.cisco.com/community/netpro/security/intrusion-prevention&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also check the product documentation here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/ps5058/tsd_products_support_model_home.html"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/ps5058/tsd_products_support_model_home.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 19:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569433#M66033</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-12-09T19:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM handling IP Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569434#M66034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any update?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 10:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569434#M66034</guid>
      <dc:creator>szekahungdanny</dc:creator>
      <dc:date>2010-12-14T10:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM handling IP Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569435#M66035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello szekahungdanny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This would require the IDSM-2 to maintain a table of IP/MAC correlation. This is not a function of the IDSM. What you are looking for is the ip source guard feature of the Catalyst switches: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/ipsrcgrd.html"&gt;http://www.cisco.com/en/US/partner/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/ipsrcgrd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if I can help you with anything further within the context of this thread. If your question has been Answered, please mark the thread as such so that it will be helpful to other users. Also, please feel free to Rate this thread to reflect your experience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Blayne Dreier&lt;BR /&gt;Cisco TAC Escalation Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Please check out our Podcasts**&lt;BR /&gt;&lt;SPAN&gt;TAC Security Show: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go/tacsecuritypodcast"&gt;http://www.cisco.com/go/tacsecuritypodcast&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;TAC IPS Media Series: &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-12758"&gt;https://supportforums.cisco.com/docs/DOC-12758&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 19:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-handling-ip-spoofing/m-p/1569435#M66035</guid>
      <dc:creator>Christopher Dreier</dc:creator>
      <dc:date>2011-02-07T19:44:49Z</dc:date>
    </item>
  </channel>
</rss>

