<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CISCO IPS 4255 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257631#M76940</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your sensor in-line or sniffing in promiscious mode? If it is in-line then you can drop the packets instead of sending a TCP Reset. If your sesor is promiscious, then you need a method of transmitting those resets back into the traffic stream.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Jun 2009 17:35:38 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2009-06-12T17:35:38Z</dc:date>
    <item>
      <title>CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257630#M76939</link>
      <description>&lt;P&gt;Hi Friend &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco IPS 4255, and I put all the upgrades that Cisco recomend. So, I put the ARES signature with TCP RESET like the action, but the ARES is working without the problem, and I need to stop these traffic. How can I stop the ARES P2P traffic.&lt;/P&gt;&lt;P&gt;I will wait your answer.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rafael Barba&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257630#M76939</guid>
      <dc:creator>r.barba</dc:creator>
      <dc:date>2019-03-10T11:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257631#M76940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is your sensor in-line or sniffing in promiscious mode? If it is in-line then you can drop the packets instead of sending a TCP Reset. If your sesor is promiscious, then you need a method of transmitting those resets back into the traffic stream.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2009 17:35:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257631#M76940</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-06-12T17:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257632#M76941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi friend thank you for your answer, my sensor is in-line mode, and I have configured the signture with both actions.&lt;/P&gt;&lt;P&gt;TCP reset and deny inline packet???, Should I change the action to other???, please tell me wich one???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rafael Barba &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2009 20:09:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257632#M76941</guid>
      <dc:creator>r.barba</dc:creator>
      <dc:date>2009-06-12T20:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257633#M76942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your sensor is physically in-line then you only need to drop. Are your ARES signatures firing?&lt;/P&gt;&lt;P&gt;Check your alert log with "show event alert past 01:00" to see the past 1 hour of signature alerts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2009 21:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257633#M76942</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-06-12T21:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257634#M76943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi friend.&lt;/P&gt;&lt;P&gt;Thank you for your answer, You know that the ARES signatures is not firing, I don not why??? I am sending 2 pictures ipslog1.jpg (is my signatures configuration), ipslog2.jpg (is the action configuration), What must I do in order to fix this issue.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rafael Barba &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Jun 2009 23:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257634#M76943</guid>
      <dc:creator>r.barba</dc:creator>
      <dc:date>2009-06-12T23:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257635#M76944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi friend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any answer, about hi can I block the ARES with the IPS 4255??, I sent you my signature configuration, but I did not receive nothing. Could you help me??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rafael Barba&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2009 18:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257635#M76944</guid>
      <dc:creator>r.barba</dc:creator>
      <dc:date>2009-06-24T18:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: CISCO IPS 4255</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257636#M76945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;check to see if your ARES is triggering that IPS signature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jul 2009 06:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-4255/m-p/1257636#M76945</guid>
      <dc:creator>michael.d.brown</dc:creator>
      <dc:date>2009-07-01T06:11:51Z</dc:date>
    </item>
  </channel>
</rss>

