<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Sensor not seeing all traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528802#M66451</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; It does sounds like it may have been coincidental - but should you have concern over the behavior in the future, just let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; As for reasons to upgrade from 6.2 to 7.0 IPS software, the addition of global correlation allows additional defensive mechanisms for protecting you network.&amp;nbsp; You can find out more about global correlation here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_collaboration.html#wp1056492"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_collaboration.html#wp1056492&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Sep 2010 15:58:10 GMT</pubDate>
    <dc:creator>Scott Fringer</dc:creator>
    <dc:date>2010-09-28T15:58:10Z</dc:date>
    <item>
      <title>IPS Sensor not seeing all traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528799#M66444</link>
      <description>&lt;P&gt;We upgraded all our ASA's last weekend to 8.2.3.&amp;nbsp; The IPS modules were left on the version of code they were using when the ASA's were on 8.0.4.32.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the upgrade, I am seeing something on the IPS sensors that doesnt make sense.&amp;nbsp; When looking at the real time monitor, I am only seeing internal traffic addresses showing up in the attacker column and outside ip addresses showing up on the victim column in IPS ME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config lines from the ASA as it concerns the IPS Module -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ips extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map ips&lt;BR /&gt;match access-list ips&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class ips&lt;BR /&gt;&amp;nbsp; ips inline fail-open sensor vs0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I understand it, how you control what traffic the IPS Sensor sees is controlled at the ASA, not the IPS module.&lt;/P&gt;&lt;P&gt;The ASA is operating normally and I can see the traffic I would expect to on the inside and outside interfaces.&amp;nbsp; I am starting to suspect a bug in the new ASA code but wanted to see if anyone else had seen this before I&amp;nbsp; called TAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528799#M66444</guid>
      <dc:creator>Ronald Nutter</dc:creator>
      <dc:date>2019-03-10T12:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Sensor not seeing all traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528800#M66447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You are correct that the configured policy map controls the traffic that is diverted to the AIP-SSM for inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I've not encountered the behavior you are decribing.&amp;nbsp; What version of software is present on the AIP-SSM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; What is the most common signature event that is firing (possibly 3030/0)?&amp;nbsp; It is possible that you have internal traffic that is frequently matching on a signature and this will cause those addresses to be listed as the attackers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; From the CLI of the AIP-SSM, if you issue the following command, do you see traffic sourced from both internal and external hosts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;packet display gigabitethernet0/1&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can terminate this output by issuing ctrl-c.&amp;nbsp; If this output does include traffic sourced from both internal and external hosts, the ASA is sending the traffic as expected.&amp;nbsp; It will be necessary at this point to dig further into the firing events on the AIP-SSM to verify expected output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 11:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528800#M66447</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-09-28T11:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Sensor not seeing all traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528801#M66448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the command.&amp;nbsp; I can see two way traffic.&amp;nbsp; That confirms that I am seeing in IPS ME.&amp;nbsp; I have 5 IPS sensors I am watching. They are running 6.2.2.E4.&amp;nbsp; I have a test sensor in the lab that is on 7.0.2.E4.&amp;nbsp; I am considering moving to 7.x but our local Cisco office has advised me to wait for the time being (that conversation was a while back - havent seen a reason to move from the 6.2 train to 7.x).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I normally dont go more than a day with getting an alert about a signature firing.&amp;nbsp; It has been quiet for a while now.&amp;nbsp; That change in behavior occured around the same time as the upgarde on the ASA to 8.2.3.&amp;nbsp; It may be purely coincidental.&amp;nbsp; Just trying to err on the side of caution.&amp;nbsp; Maybe a finally have it tuned to an optimal level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 15:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528801#M66448</guid>
      <dc:creator>Ronald Nutter</dc:creator>
      <dc:date>2010-09-28T15:54:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Sensor not seeing all traffic</title>
      <link>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528802#M66451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; It does sounds like it may have been coincidental - but should you have concern over the behavior in the future, just let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; As for reasons to upgrade from 6.2 to 7.0 IPS software, the addition of global correlation allows additional defensive mechanisms for protecting you network.&amp;nbsp; You can find out more about global correlation here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_collaboration.html#wp1056492"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_collaboration.html#wp1056492&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 15:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sensor-not-seeing-all-traffic/m-p/1528802#M66451</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-09-28T15:58:10Z</dc:date>
    </item>
  </channel>
</rss>

