<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2821 IPS Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432180#M67326</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;OK ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see where this might be a problem......look at this:&lt;/P&gt;&lt;P&gt;#show ip inspect stat&lt;/P&gt;&lt;P&gt;Packet inspection statistics [process switch:fast switch]&lt;/P&gt;&lt;P&gt;tcp packets: [62594:7893336]&lt;/P&gt;&lt;P&gt;udp packets: [8:1161529]&lt;/P&gt;&lt;P&gt;icmp packets: [3383:1134178]&lt;/P&gt;&lt;P&gt;http packets: [17:1206216]&lt;/P&gt;&lt;P&gt;ftp packets: [0:89209]&lt;/P&gt;&lt;P&gt;Interfaces configured for inspection 14&lt;/P&gt;&lt;P&gt;Session creations since subsystem startup or last reset 812333&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [39:20:0]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [114:92:4]&lt;/P&gt;&lt;P&gt;Last session created 00:00:00&lt;/P&gt;&lt;P&gt;Last statistic reset never Last session creation rate 121&lt;/P&gt;&lt;P&gt;Maxever session creation rate 322&lt;/P&gt;&lt;P&gt;Last half-open session total 20&lt;/P&gt;&lt;P&gt;TCP reassembly statistics&lt;/P&gt;&lt;P&gt;received 147 packets out-of-order; dropped 0&lt;/P&gt;&lt;P&gt;peak memory usage 39 KB;&lt;/P&gt;&lt;P&gt;current usage: 0 KB&lt;/P&gt;&lt;P&gt;peak queue length 16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a few questions......why would removing the ip ips statements from the interface stop this? I'm not second guessing you just trying to get a better understanding of what's going on....Does having the ip ips enabled on an interface enable the firewall on that interface? I thought the ip inspect rules were on all of the time is that not true??? Could I test this by removing the ip inspect rules? And if it allows the traffic I could adjust the max incomplete-high values?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jun 2010 10:34:42 GMT</pubDate>
    <dc:creator>JamesBrockman</dc:creator>
    <dc:date>2010-06-03T10:34:42Z</dc:date>
    <item>
      <title>2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432176#M67314</link>
      <description>&lt;P&gt;We have a 2821 that is blocking telnet among other things (windows password changes) (setup new account on windowws) when we have an ip ips XXXX in or out statment on a sub interface/vlan.....if we remove the statment everything works replace it and it breaks. The logs shows servral of these:&lt;/P&gt;&lt;P&gt;Jun&amp;nbsp; 2 06:18:21.668 est: %IPS-4-SIGNATURE: Sig:6055 Subsig:2 Sev:100 DNS Inverse Query Buffer Overflow [10.129.14.76:53 -&amp;gt; 10.105.248.2:52279] VRF:NONE RiskRating:100.....anyone know how I could test to see what is going on?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432176#M67314</guid>
      <dc:creator>JamesBrockman</dc:creator>
      <dc:date>2019-03-10T12:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432177#M67317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; What version of IOS is running on your 2821?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Are there any other signature events in the router's log?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can monitor IPS signature&amp;nbsp; events by issuing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: terminal,monaco; "&gt;sh ip sdee events&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; This requires that IPS notifications via SDEE be enabled.&amp;nbsp; You can also get a summary of IPS activity by issuing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt; font-family: terminal,monaco; "&gt;sh ip ips stat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Is the traffic being impacted the same traffic indicated by the signature (6055/2) you supplied?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 18:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432177#M67317</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-02T18:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432178#M67320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; What version of IOS is running on your 2821?&amp;nbsp; &lt;SPAN style="color: #ff6600;"&gt;(C2800NM-ADVENTERPRISEK9-M), Version 15.1(1)T&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Are there any other signature events in the router's log? &lt;SPAN style="color: #ff0000;"&gt;Some like this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;May 29 02:15:06.633 est: %IPS-4-SIGNATURE: Sig:5605 Subsig:0 Sev:25 Windows Account Locked [10.105.248.117:1038 -&amp;gt; 10.129.14.7:139] VRF:NONE RiskRating:21&lt;BR /&gt;May 28 13:38:10.838 est: %IPS-3-SIG_UPDATE_REQUIRED: IOS IPS requires a signature update package to be loaded&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Some other stuff but it was expected...links going up and down&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can monitor IPS signature&amp;nbsp; events by issuing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ip sdee events&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt; it only shows this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt; 40: 02:15:06 est May 29 2010&amp;nbsp; ALERT&amp;nbsp;&amp;nbsp; Sig ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5605:0&amp;nbsp; Windows Account Locked&lt;BR /&gt;&amp;nbsp; 41: 06:18:19 est May 29 2010&amp;nbsp; ALERT&amp;nbsp;&amp;nbsp; Sig ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6055:2&amp;nbsp; DNS Inverse Query Buffer Overflow&lt;BR /&gt;&amp;nbsp; 42: 06:18:19 est May 29 2010&amp;nbsp; ALERT&amp;nbsp;&amp;nbsp; Sig ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6055:2&amp;nbsp; DNS Inverse Query Buffer Overflow&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; This requires that IPS notifications via SDEE be enabled.&amp;nbsp; You can also get a summary of IPS activity by issuing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ip ips stat &lt;SPAN style="color: #ff0000;"&gt;it shows &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt; show ip ips stat&lt;BR /&gt;Signature statistics [process switch:fast switch]&lt;BR /&gt;&amp;nbsp; signature 5605:0: packets checked [0:5] alarmed [0:5] dropped [0:0]&lt;BR /&gt;&amp;nbsp; signature 3124:0: packets checked [0:1] alarmed [0:1] dropped [0:0]&lt;BR /&gt;&amp;nbsp; signature 6055:2: packets checked [0:64] alarmed [0:64] dropped [0:0]&lt;BR /&gt;Interfaces configured for ips 5&lt;BR /&gt;Session creations since subsystem startup or last reset 563699&lt;BR /&gt;Current session counts (estab/half-open/terminating) [134126:85004:0]&lt;BR /&gt;Maxever session counts (estab/half-open/terminating) [134131:85012:8]&lt;BR /&gt;Last session created 00:00:58&lt;BR /&gt;Last statistic reset never&lt;BR /&gt;TCP reassembly statistics&lt;BR /&gt;&amp;nbsp; received 908 packets out-of-order; dropped 12&lt;BR /&gt;&amp;nbsp; peak memory usage 39 KB; current usage: 0 KB&lt;BR /&gt;&amp;nbsp; peak queue length 16&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Is the traffic being impacted the same traffic indicated by the signature (6055/2) you supplied? &lt;SPAN style="color: #ff0000;"&gt;I'm not so sure....it just seems strange that if we remove the statment from the interface everything works....when we put it back it stops...we've tried removing and reloading then replacing the sigs....downloading the sigs again then reloading....this blocks traffic from one vlan to another only....it worked for 3 weeks then the power went out 2 weeks ago and after that we have had this problem.....if&lt;EM&gt;&amp;nbsp; &lt;/EM&gt;I had to guess the problem was there and the unexpected reload just triggered it....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm really stuck on this one...&lt;/P&gt;&lt;P&gt;'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 18:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432178#M67320</guid>
      <dc:creator>JamesBrockman</dc:creator>
      <dc:date>2010-06-02T18:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432179#M67323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; From the output provided, the traffic impact is not from the signatures that are firing (none have taken a drop action).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; One thing to note with IOS IPS, once it is enabled some of the underlying firewall functionality is enabled to provide some protection from DoS attacks.&amp;nbsp; You may need to tune these parameters as outlined in this document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6634/prod_white_paper0900aecd8062acfb.html"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6634/prod_white_paper0900aecd8062acfb.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; specifically the section titled,"&lt;SPAN class="content"&gt;Understanding the Inspection Threshold Values".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; There appears to be an issue with out-of-order traffic arriving and being dropped:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;SPAN style="color: #000000;"&gt;TCP reassembly statistics&lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN style="color: #000000;"&gt; received 908 packets out-of-order; dropped 12&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 19:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432179#M67323</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-02T19:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432180#M67326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;OK ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see where this might be a problem......look at this:&lt;/P&gt;&lt;P&gt;#show ip inspect stat&lt;/P&gt;&lt;P&gt;Packet inspection statistics [process switch:fast switch]&lt;/P&gt;&lt;P&gt;tcp packets: [62594:7893336]&lt;/P&gt;&lt;P&gt;udp packets: [8:1161529]&lt;/P&gt;&lt;P&gt;icmp packets: [3383:1134178]&lt;/P&gt;&lt;P&gt;http packets: [17:1206216]&lt;/P&gt;&lt;P&gt;ftp packets: [0:89209]&lt;/P&gt;&lt;P&gt;Interfaces configured for inspection 14&lt;/P&gt;&lt;P&gt;Session creations since subsystem startup or last reset 812333&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [39:20:0]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [114:92:4]&lt;/P&gt;&lt;P&gt;Last session created 00:00:00&lt;/P&gt;&lt;P&gt;Last statistic reset never Last session creation rate 121&lt;/P&gt;&lt;P&gt;Maxever session creation rate 322&lt;/P&gt;&lt;P&gt;Last half-open session total 20&lt;/P&gt;&lt;P&gt;TCP reassembly statistics&lt;/P&gt;&lt;P&gt;received 147 packets out-of-order; dropped 0&lt;/P&gt;&lt;P&gt;peak memory usage 39 KB;&lt;/P&gt;&lt;P&gt;current usage: 0 KB&lt;/P&gt;&lt;P&gt;peak queue length 16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a few questions......why would removing the ip ips statements from the interface stop this? I'm not second guessing you just trying to get a better understanding of what's going on....Does having the ip ips enabled on an interface enable the firewall on that interface? I thought the ip inspect rules were on all of the time is that not true??? Could I test this by removing the ip inspect rules? And if it allows the traffic I could adjust the max incomplete-high values?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 10:34:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432180#M67326</guid>
      <dc:creator>JamesBrockman</dc:creator>
      <dc:date>2010-06-03T10:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432181#M67328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; I do not work directly with the firewall feature set, but from my understanding if you are not enabling the firewall features specifically, enabling the IPS feature set will enable (but not expose) the firewall thresholds.&amp;nbsp; You should be able to adjust the necessary thresholds to achieve a balance for your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Disabling the IPS feature, will in turn remove the firewall thresholds as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 11:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432181#M67328</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-03T11:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432182#M67329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I think I get it now....I'll adjust the IP Inspect "number of connections" and see if that solves the issue....just another side note....I could replacate this at will....add the ip ips statment and it doesn't work...take it out it does...would that mean that just the one telnet session would push it over the limit? Everything else seemed to be ok....&lt;SPAN style="color: #0000ff;"&gt;on another subnet the same issue with logging into a domain for the first time or changing your passwword but not an issue if you have logged in before Blue=tested by another person....but the same fix works...&lt;/SPAN&gt;&lt;SPAN style="color: #000000;"&gt;again thanks for your help....I'll let you know how it goes...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #f8fafd;"&gt;James&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 11:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432182#M67329</guid>
      <dc:creator>JamesBrockman</dc:creator>
      <dc:date>2010-06-03T11:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: 2821 IPS Problem</title>
      <link>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432183#M67330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did changing the "number of connections" fixes your problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Nov 2010 14:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/2821-ips-problem/m-p/1432183#M67330</guid>
      <dc:creator>roel</dc:creator>
      <dc:date>2010-11-22T14:57:56Z</dc:date>
    </item>
  </channel>
</rss>

