<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO IPS - IDS MODE-TCP RESET  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345367#M68576</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is that because, a tcp reset will be sent to vlan 145 against any traffic without a vlan tag.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Oct 2009 18:37:10 GMT</pubDate>
    <dc:creator>manuadoor</dc:creator>
    <dc:date>2009-10-02T18:37:10Z</dc:date>
    <item>
      <title>CISCO IPS - IDS MODE-TCP RESET</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345362#M68570</link>
      <description>&lt;P&gt;I would like to issue TCP resets thru promiscuous interface of cisco IPS 4240. As per the current setup (which is explained in the attached drawing) there is only one vlan between firewall and switch and its working fine with following configurations in switch &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;monitor session 1 source interface fastethernet0/5&lt;/P&gt;&lt;P&gt;monitor session 1 destination interface fastethernet0/14 ingress vlan 145&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is, if we have multiple vlan in between switch and firewall. How the configuration should be? any extra configuration required in IPS as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345362#M68570</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2019-03-10T11:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS - IDS MODE-TCP RESET</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345363#M68572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the switch, instead of using interface as the monitor source, use VLANS and in the monitor destination any one vlan is required. &lt;/P&gt;&lt;P&gt;The IPS will send the TCP RST packet via that vlan.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;monitor session 1 source vlan 145,146,147&lt;/P&gt;&lt;P&gt;monitor session 1 destination interface f0/14 ingress vlan 145&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no change on the IPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Sep 2009 14:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345363#M68572</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2009-09-30T14:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS - IDS MODE-TCP RESET</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345364#M68573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are limited to only sending TCP resets to one VLAN when you send them out the sniffing interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Sep 2009 16:03:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345364#M68573</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-09-30T16:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS - IDS MODE-TCP RESET</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345365#M68574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can I know why we are using vlan 145 after ingress command. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Oct 2009 01:23:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345365#M68574</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2009-10-01T01:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS - IDS MODE-TCP RESET</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345366#M68575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 145 is used after ingress command because the IPS will send the TCP RST packet via that vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Oct 2009 17:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345366#M68575</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2009-10-02T17:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS - IDS MODE-TCP RESET</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345367#M68576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is that because, a tcp reset will be sent to vlan 145 against any traffic without a vlan tag.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Oct 2009 18:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-ids-mode-tcp-reset/m-p/1345367#M68576</guid>
      <dc:creator>manuadoor</dc:creator>
      <dc:date>2009-10-02T18:37:10Z</dc:date>
    </item>
  </channel>
</rss>

