<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Layer 4 http access issue IPS 4270-20 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/layer-4-http-access-issue-ips-4270-20/m-p/1364020#M67646</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please assume one server connected to any of DMZ switch 2960 shown in the network diag as i have missed it there for brevity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Thanks anyways the issue has been resolved now.It was due to anamoly signature detections. We are still monitoring it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Apr 2010 06:45:24 GMT</pubDate>
    <dc:creator>xs.gautam</dc:creator>
    <dc:date>2010-04-15T06:45:24Z</dc:date>
    <item>
      <title>Layer 4 http access issue IPS 4270-20</title>
      <link>https://community.cisco.com/t5/network-security/layer-4-http-access-issue-ips-4270-20/m-p/1364019#M67645</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PFA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are facing an issue while accessing one of our Server in DMZ, which is connected to 2960 switch in DMZ from inside segment of ASA.&lt;/P&gt;&lt;P&gt;We have two IPS boxes which are connected as per network diag attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are able to access that particular server in DMZ&amp;nbsp; when Primary PIX is active &amp;amp; Primary ASA is active, from inside zone of ASA. &lt;/P&gt;&lt;P&gt;But as when PIX failover (Secondary is active ) I am not able to have http access to server though ping works fine. Also when ASA also failover&lt;/P&gt;&lt;P&gt;(Secondary ASA is active) problem gets resolved and http access to server is available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two IPS have been connected in Inline mode as per netdiag, with default signature &amp;amp; event action policy.&lt;/P&gt;&lt;P&gt;If we bypass the IPS by directly connecting PIX to DMZ switch, server is http accessible again. But as IPS is again enabled, http stops but ping works.&lt;/P&gt;&lt;P&gt;We suspected IPS blocking it but there are no event logs on both IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anyway we can bypass traffic for that particular server through IPS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you need anything to troubleshoot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gautam&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/layer-4-http-access-issue-ips-4270-20/m-p/1364019#M67645</guid>
      <dc:creator>xs.gautam</dc:creator>
      <dc:date>2019-03-10T11:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Layer 4 http access issue IPS 4270-20</title>
      <link>https://community.cisco.com/t5/network-security/layer-4-http-access-issue-ips-4270-20/m-p/1364020#M67646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please assume one server connected to any of DMZ switch 2960 shown in the network diag as i have missed it there for brevity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Thanks anyways the issue has been resolved now.It was due to anamoly signature detections. We are still monitoring it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Apr 2010 06:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/layer-4-http-access-issue-ips-4270-20/m-p/1364020#M67646</guid>
      <dc:creator>xs.gautam</dc:creator>
      <dc:date>2010-04-15T06:45:24Z</dc:date>
    </item>
  </channel>
</rss>

