<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic inspecting l2tp traffic using AIM-IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184209#M77420</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have an IPS module in a ASA via which we are planning to send l2tp traffic. Would it be possible for the IPS to insoect this traffic as it normmaly does with other traffic ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:34:09 GMT</pubDate>
    <dc:creator>thedinuka</dc:creator>
    <dc:date>2019-03-10T11:34:09Z</dc:date>
    <item>
      <title>inspecting l2tp traffic using AIM-IPS</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184209#M77420</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have an IPS module in a ASA via which we are planning to send l2tp traffic. Would it be possible for the IPS to insoect this traffic as it normmaly does with other traffic ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:34:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184209#M77420</guid>
      <dc:creator>thedinuka</dc:creator>
      <dc:date>2019-03-10T11:34:09Z</dc:date>
    </item>
    <item>
      <title>Re: inspecting l2tp traffic using AIM-IPS</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184210#M77421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes this is possible for the IPS to inspect as the traffic is decrypted before it is processed by the AIP-SSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is providing the ASA with the module in is terminating the l2TP connection &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 14:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184210#M77421</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2009-03-25T14:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: inspecting l2tp traffic using AIM-IPS</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184211#M77422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for the response. But two points I need to clarify&lt;/P&gt;&lt;P&gt;We would not be using the ASA to terminate the l2tp tunnel. It will simply pass through the ASA to a router at which the tunnel is terminated.&lt;/P&gt;&lt;P&gt;Also, by default l2tp traffic is not encrypted right ? It is just encapsulation. It it was decrypted, then I know for sure that the IPS will not be able to inspect it. But since it is not, then theoretically the IPS should be capable of inspecting it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the question is whether my hypothesis here is correct ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks again &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Mar 2009 02:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184211#M77422</guid>
      <dc:creator>thedinuka</dc:creator>
      <dc:date>2009-03-26T02:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: inspecting l2tp traffic using AIM-IPS</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184212#M77423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To inspect l2tp traffic the sensor software has to understand that their is an additional header on the packet in order to understand how to get to the packet inside the tunnel header.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately the Cisco IPS Sensor software has not been coded to recognize an l2tp header and so does not know how to get to the underlying packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Cisco IPS Sensor has only been coded to recognize and analyze packets within GRE, MPLES, IPV4inIPV4, and IPV4inIPV6 tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Mar 2009 17:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184212#M77423</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2009-03-26T17:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: inspecting l2tp traffic using AIM-IPS</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184213#M77424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Many thanks for the short and sweet answer. So the IPS will not inspect the l2tp traffic. Since it doesn't identify the traffic type, will it drop these ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Din&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2009 03:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184213#M77424</guid>
      <dc:creator>thedinuka</dc:creator>
      <dc:date>2009-03-27T03:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: inspecting l2tp traffic using AIM-IPS</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184214#M77425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IPS will do some very basic signature checking on the first IPv4 packet header.  &lt;/P&gt;&lt;P&gt;If the first header looks fine, then it should pass the packet through without further analysis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2009 14:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-l2tp-traffic-using-aim-ips/m-p/1184214#M77425</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2009-03-27T14:02:33Z</dc:date>
    </item>
  </channel>
</rss>

