<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: test signature in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/test-signature/m-p/1503468#M67191</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The easiest thing to do is enable signatures 2000/0 and 2004/0.&amp;nbsp; These two signatures detect ICMP echo requests and replies.&amp;nbsp; You can then source a ping from a machine you can access to a machine located outside your network.&amp;nbsp; The resulting traffic should traverse your sensor and fire both signatures.&amp;nbsp; Once you verify those signatures fire, you will want to disable them as they can be very active signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jun 2010 17:36:26 GMT</pubDate>
    <dc:creator>Scott Fringer</dc:creator>
    <dc:date>2010-06-15T17:36:26Z</dc:date>
    <item>
      <title>test signature</title>
      <link>https://community.cisco.com/t5/network-security/test-signature/m-p/1503467#M67190</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I make sure my IDS is running?&amp;nbsp; Is there some tool I can use to trigger an event?&amp;nbsp; Something like the EICAR test virus?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:01:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-signature/m-p/1503467#M67190</guid>
      <dc:creator>ericb_summit</dc:creator>
      <dc:date>2019-03-10T12:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: test signature</title>
      <link>https://community.cisco.com/t5/network-security/test-signature/m-p/1503468#M67191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eric;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The easiest thing to do is enable signatures 2000/0 and 2004/0.&amp;nbsp; These two signatures detect ICMP echo requests and replies.&amp;nbsp; You can then source a ping from a machine you can access to a machine located outside your network.&amp;nbsp; The resulting traffic should traverse your sensor and fire both signatures.&amp;nbsp; Once you verify those signatures fire, you will want to disable them as they can be very active signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jun 2010 17:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-signature/m-p/1503468#M67191</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-15T17:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: test signature</title>
      <link>https://community.cisco.com/t5/network-security/test-signature/m-p/1503469#M67195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please advise where I should look if those signatures fire? I was looking in IDM (ver 6.0) &amp;gt; Monitoring but it doesn't look like there or pinging to a machine outside doesn't fire. Thanks for your advice in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ASA 5510 with the AIP-SSM-10 in promicuous mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA 5510 : ASA version 7.0 (8)&lt;/P&gt;&lt;P&gt;AIP-SSM-10: IPS version 6.0(5)E2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Lay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Oct 2011 02:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/test-signature/m-p/1503469#M67195</guid>
      <dc:creator>layhlaing</dc:creator>
      <dc:date>2011-10-17T02:20:42Z</dc:date>
    </item>
  </channel>
</rss>

