<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS 4240 virtual sensor asymmetric mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425541#M67827</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customers have a 4240 IPS on which there is one inline pair and 2 promiscuous interfaces.&lt;/P&gt;&lt;P&gt;The inline pair is used between an internet router and a switch on which is connected a pair of ASAs.&lt;/P&gt;&lt;P&gt;The problem happens when we connect the inline pair, sudeenly and after a random period of time ranging from 2 to 4 hours, and although the upload trafic on the internet router is limited by the ISP to 500 Kbps, we see bursts of 6 Mbps and disconnection for the internet link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to set the virtual sensor inline-TCP-evasion-protection-mode to asymmetric instead of the default set to strict, I think this has solved the problem untill now( first day of monitoring) but I need to know how it resolved it??????&lt;/P&gt;&lt;P&gt;What does the asymmetric mode exactly do? ( Please provide additional information than the original documentation whihc is not very informative)&lt;/P&gt;&lt;P&gt;And how could it solve the problem in my case?&lt;/P&gt;&lt;P&gt;btw I'm using multiple virtual sensors for each of the inline pair and the rest of the two promiscuous interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:55:41 GMT</pubDate>
    <dc:creator>k.abillama</dc:creator>
    <dc:date>2019-03-10T11:55:41Z</dc:date>
    <item>
      <title>IPS 4240 virtual sensor asymmetric mode</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425541#M67827</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our customers have a 4240 IPS on which there is one inline pair and 2 promiscuous interfaces.&lt;/P&gt;&lt;P&gt;The inline pair is used between an internet router and a switch on which is connected a pair of ASAs.&lt;/P&gt;&lt;P&gt;The problem happens when we connect the inline pair, sudeenly and after a random period of time ranging from 2 to 4 hours, and although the upload trafic on the internet router is limited by the ISP to 500 Kbps, we see bursts of 6 Mbps and disconnection for the internet link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to set the virtual sensor inline-TCP-evasion-protection-mode to asymmetric instead of the default set to strict, I think this has solved the problem untill now( first day of monitoring) but I need to know how it resolved it??????&lt;/P&gt;&lt;P&gt;What does the asymmetric mode exactly do? ( Please provide additional information than the original documentation whihc is not very informative)&lt;/P&gt;&lt;P&gt;And how could it solve the problem in my case?&lt;/P&gt;&lt;P&gt;btw I'm using multiple virtual sensors for each of the inline pair and the rest of the two promiscuous interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425541#M67827</guid>
      <dc:creator>k.abillama</dc:creator>
      <dc:date>2019-03-10T11:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 virtual sensor asymmetric mode</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425542#M67829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you set the "inline-TCP-evasion-protection-mode" to asymmetric, it does not enforce a receipt of the TCP ACK before analysing/inspecting and transmitting the TCP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the mode is set to strict, the engine buffers the connection and waits for the ACK packet before starting to analyse/inspect and transmit the TCP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2010 04:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425542#M67829</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-18T04:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 virtual sensor asymmetric mode</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425543#M67830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx a lot for the info! Is there a drawback to keep it in asymmetric mode in my scenario( internet facing IPS) What do I lose exactly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2010 07:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425543#M67830</guid>
      <dc:creator>k.abillama</dc:creator>
      <dc:date>2010-03-18T07:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 virtual sensor asymmetric mode</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425544#M67831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately there is always trade-off between security vs performance.&lt;/P&gt;&lt;P&gt;By turning the inline-TCP-evasion-protection-mode to asymmetric, it is essentially turning off the TCP normalizer engine which leaves the network vulnerable to evasion techniques (specific to TCP protocol), ie: the 1300 range signatures.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2010 08:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425544#M67831</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-18T08:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 virtual sensor asymmetric mode</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425545#M67832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok! thx &lt;/P&gt;&lt;P&gt;Do you know how in my case we had this burst of upload trafic and disconnection when the mode was set to strict, the customer need some explanantions &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2010 11:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425545#M67832</guid>
      <dc:creator>k.abillama</dc:creator>
      <dc:date>2010-03-18T11:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 virtual sensor asymmetric mode</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425546#M67833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are possibilities that those TCP traffic does not comply to normal TCP standard, and it is being picked up by the normalizer engine, and they are either being dropped, OR/ due to the nature of "strict" mode, it waited for the ACK before it performs the inspection hence the burst of traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2010 12:01:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-virtual-sensor-asymmetric-mode/m-p/1425546#M67833</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-18T12:01:55Z</dc:date>
    </item>
  </channel>
</rss>

