<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM not gettint outside traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-not-gettint-outside-traffic/m-p/1372358#M68079</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you policy-map applied with a "service-policy"? Please make sure they do.&lt;/P&gt;&lt;P&gt;What traffic is the aip class-map matching? Is it matching all traffic? Please make sure it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 31 Jan 2010 16:44:58 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-01-31T16:44:58Z</dc:date>
    <item>
      <title>AIP-SSM not gettint outside traffic</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-not-gettint-outside-traffic/m-p/1372357#M68078</link>
      <description>&lt;P&gt;Hi all. I have a AIP-ssm 10 and I created two class-map.. one for inside and one for the outside.. and applyed like the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp&lt;/P&gt;&lt;P&gt;policy-map outside-policy&lt;/P&gt;&lt;P&gt; class outside-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; ips inline fail-open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map inside-policy&lt;/P&gt;&lt;P&gt; class inside-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; ips inline fail-open&lt;/P&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I also tryed with the global policy but the result was the same... I don't get nothing in the alerts... when i receive something... is from the inside network..&lt;/DIV&gt;&lt;DIV&gt;But from outside.. i have nothing... and I tryed to make some scans.. but.. nothing happend...&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Here is the configuration of the IDS....&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Could someone help me?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I Also tryed this solution... &lt;A class="active_link" href="https://community.cisco.com/message/1323736#1323736" target="_blank"&gt;https://supportforums.cisco.com/message/1323736#1323736&lt;/A&gt; but... has no effect....&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Thanks in advance...&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Fabio&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;! Current configuration last modified Thu Jan 28 18:05:49 2010&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;! Version 7.0(2)&lt;/DIV&gt;&lt;DIV&gt;! Host:&lt;/DIV&gt;&lt;DIV&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Realm Keys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key1.0&lt;/DIV&gt;&lt;DIV&gt;! Signature Definition:&lt;/DIV&gt;&lt;DIV&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Update&amp;nbsp;&amp;nbsp;&amp;nbsp; S458.0&amp;nbsp;&amp;nbsp; 2010-01-04&lt;/DIV&gt;&lt;DIV&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Virus Update&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; V1.4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2007-03-02&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service interface&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service authentication&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service event-action-rules rules0&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service host&lt;/DIV&gt;&lt;DIV&gt;network-settings&lt;/DIV&gt;&lt;DIV&gt;host-ip 192.168.100.201/24,192.168.100.1&lt;/DIV&gt;&lt;DIV&gt;host-name IPS02&lt;/DIV&gt;&lt;DIV&gt;telnet-option disabled&lt;/DIV&gt;&lt;DIV&gt;access-list 10.10.110.0/24&lt;/DIV&gt;&lt;DIV&gt;access-list 172.27.1.0/24&lt;/DIV&gt;&lt;DIV&gt;access-list 172.27.20.0/24&lt;/DIV&gt;&lt;DIV&gt;dns-primary-server enabled&lt;/DIV&gt;&lt;DIV&gt;address 172.27.1.7&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;dns-secondary-server enabled&lt;/DIV&gt;&lt;DIV&gt;address 172.27.1.3&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;dns-tertiary-server enabled&lt;/DIV&gt;&lt;DIV&gt;address 172.27.1.8&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;time-zone-settings&lt;/DIV&gt;&lt;DIV&gt;offset -180&lt;/DIV&gt;&lt;DIV&gt;standard-time-zone-name GMT-03:00&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;ntp-option enabled-ntp-unauthenticated&lt;/DIV&gt;&lt;DIV&gt;ntp-server 172.27.1.7&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service logger&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service network-access&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service notification&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service signature-definition sig0&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service ssh-known-hosts&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service trusted-certificates&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service web-server&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service anomaly-detection ad0&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service external-product-interface&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service health-monitor&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service global-correlation&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;! ------------------------------&lt;/DIV&gt;&lt;DIV&gt;service analysis-engine&lt;/DIV&gt;&lt;DIV&gt;virtual-sensor vs0&lt;/DIV&gt;&lt;DIV&gt;anomaly-detection&lt;/DIV&gt;&lt;DIV&gt;operational-mode detect&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;physical-interface GigabitEthernet0/1&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt;exit&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-not-gettint-outside-traffic/m-p/1372357#M68078</guid>
      <dc:creator>fabiossilva</dc:creator>
      <dc:date>2019-03-10T11:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM not gettint outside traffic</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-not-gettint-outside-traffic/m-p/1372358#M68079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you policy-map applied with a "service-policy"? Please make sure they do.&lt;/P&gt;&lt;P&gt;What traffic is the aip class-map matching? Is it matching all traffic? Please make sure it does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 31 Jan 2010 16:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-not-gettint-outside-traffic/m-p/1372358#M68079</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-01-31T16:44:58Z</dc:date>
    </item>
  </channel>
</rss>

