<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDS Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-question/m-p/1546307#M66264</link>
    <description>&lt;P&gt;Hi. We have a Cisco IDS 4215 along with 2x Cisco Pix 515e's. I manage the Pix's but know nothing about the IDS (neither does anyone else here, it was installed by a 3rd party long ago). We have a situation where traffic from an external supplier is occasionally getting dropped (they come in over a site-to-site VPN). We've already established (from the firewall syslogs) that the SYN-ACK packets are getting lost somewhere and I want to rule out the IDS. What would the consequences be of me switching off the IDS for 1 day? If problem persists then I can rule that out. If problem goes away then I'll know it's IDS and know where to concentrate my efforts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rex&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:10:13 GMT</pubDate>
    <dc:creator>Rex Biesty</dc:creator>
    <dc:date>2019-03-10T12:10:13Z</dc:date>
    <item>
      <title>IDS Question</title>
      <link>https://community.cisco.com/t5/network-security/ids-question/m-p/1546307#M66264</link>
      <description>&lt;P&gt;Hi. We have a Cisco IDS 4215 along with 2x Cisco Pix 515e's. I manage the Pix's but know nothing about the IDS (neither does anyone else here, it was installed by a 3rd party long ago). We have a situation where traffic from an external supplier is occasionally getting dropped (they come in over a site-to-site VPN). We've already established (from the firewall syslogs) that the SYN-ACK packets are getting lost somewhere and I want to rule out the IDS. What would the consequences be of me switching off the IDS for 1 day? If problem persists then I can rule that out. If problem goes away then I'll know it's IDS and know where to concentrate my efforts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rex&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-question/m-p/1546307#M66264</guid>
      <dc:creator>Rex Biesty</dc:creator>
      <dc:date>2019-03-10T12:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Question</title>
      <link>https://community.cisco.com/t5/network-security/ids-question/m-p/1546308#M66265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the IDS box comes in the picture after packet has been decrypted on Pix's ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a#What you can do to isolate the issue is to turn the bypass mode ON on the IDS box which would bypass packet processing and sensor merely acts as a bridge in the network, the drivers no longer sends the packet to sensorApp for processing, see if the issue persist ?&lt;/P&gt;&lt;P&gt;b#Secondly, if you have lot of assymetric traffic flowing than normalizers 1330's may be causing the packet drops, if from above a# you know for sure sensor is causing the trouble than you may enable assymetric flows through the sensor to isolate pointb#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how it goes !!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 09:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-question/m-p/1546308#M66265</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2010-10-29T09:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Question</title>
      <link>https://community.cisco.com/t5/network-security/ids-question/m-p/1546309#M66266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the packets are encrypted it doesn't make sense for SYN-ACKs to be missing. The IDS just sees encrypted UDP packet, so it can't know to drop the SYN-ACKs only. So, if that is the case, I am skeptical about it being the IDS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgs,&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 17:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-question/m-p/1546309#M66266</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-29T17:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: IDS Question</title>
      <link>https://community.cisco.com/t5/network-security/ids-question/m-p/1546310#M66267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it an IDs configuration or&lt;/P&gt;&lt;P&gt;IPS? If it is an IDS that means you have a span/monitor&lt;/P&gt;&lt;P&gt;sending traffic to the IDs and it should not be impacting your traffic.&lt;/P&gt;&lt;P&gt;An IPS does have your traffic passing through it and then you would want to&lt;/P&gt;&lt;P&gt;put it into bypass mode. Sorry if I was stating the obvious&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 20:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-question/m-p/1546310#M66267</guid>
      <dc:creator>andywt123</dc:creator>
      <dc:date>2010-10-29T20:29:49Z</dc:date>
    </item>
  </channel>
</rss>

