<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: customizing signatures question on AIP-SSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183970#M77432</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Andy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i already told  my customer to do that but the customer request is that the IPS appliance should deny the connection to these unknown real IPs but the IPS appliance deny the users totally where they cannot browse internet.&lt;/P&gt;&lt;P&gt;As i said before the signature action is "deny connection inline" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regrads&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Mar 2009 16:30:14 GMT</pubDate>
    <dc:creator>mohamed_makled</dc:creator>
    <dc:date>2009-03-25T16:30:14Z</dc:date>
    <item>
      <title>customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183964#M77426</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;actually our customer has an AIP-SSM module which is configured in inline mode.some users are appeared as attackers in the IPS event store .&lt;/P&gt;&lt;P&gt;can i deny any unwanted connection for these users without affecting on the legitimate connections of these users like internet browsing ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried to make the signature action to be "deny connection inline" but when the signature fire , the user who has appeared as an attacker is totally blocked and cannot access internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone face this issue ??&lt;/P&gt;&lt;P&gt;please advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183964#M77426</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2019-03-10T11:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183965#M77427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This requires a bit more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are thee users based on the inside network and they are browsing the internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can i ask which signatures the IPS is firing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 14:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183965#M77427</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2009-03-25T14:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183966#M77428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Andy &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;the users are in the inside network and they are browsing internet.&lt;/P&gt;&lt;P&gt;The signatures that is fired by the IPS is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3002   TCP SYN Port sweep  &lt;/P&gt;&lt;P&gt;3010   TCP High Port sweep&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 15:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183966#M77428</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2009-03-25T15:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183967#M77429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok - and so what is the source address of the attacker?  Is it the internal hosts?  one host or many and where are they trying to scan?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183967#M77429</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2009-03-25T16:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183968#M77430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Andy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source addresses of the attackers is the internal users (10.3.40.x)and (10.3.50.x)  and the victim is a real ip addresses which is unknown &lt;/P&gt;&lt;P&gt;this signature is fired for some internal users not all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183968#M77430</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2009-03-25T16:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183969#M77431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you checked your PC's for Viruses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They should not be scanning random IP Addresses like that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183969#M77431</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2009-03-25T16:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183970#M77432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Andy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i already told  my customer to do that but the customer request is that the IPS appliance should deny the connection to these unknown real IPs but the IPS appliance deny the users totally where they cannot browse internet.&lt;/P&gt;&lt;P&gt;As i said before the signature action is "deny connection inline" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regrads&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183970#M77432</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2009-03-25T16:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183971#M77433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally your customer needs to check his machines.  The signature can be disabled purely for these hosts, but i wouldn't recommend that as it defeats the point of having the IPS in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;He ideally needs to check his hosts for viruses &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:35:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183971#M77433</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2009-03-25T16:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183972#M77434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;surely , the customer will do that.&lt;/P&gt;&lt;P&gt;My question is that if the signature action is "deny connection inline" , is that will deny the attacker totally or not???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183972#M77434</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2009-03-25T16:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183973#M77435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, it will deny only the single connection from the host.  But the host will then create a new connection and that will then be blocked (if it fires a signature rule). if the connection to the internet is legitimate this will not be blocked as it is a new connection.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To block the host completley this will be 'deny attacker inline'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 16:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183973#M77435</guid>
      <dc:creator>andrew100</dc:creator>
      <dc:date>2009-03-25T16:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183974#M77436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you regarding that.&lt;/P&gt;&lt;P&gt;But although the signature action is "deny connection inline" , the internal user (attacker address) is totally denied.&lt;/P&gt;&lt;P&gt;Do you have any recommendations to know the reason for that??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Mar 2009 17:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183974#M77436</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2009-03-25T17:08:56Z</dc:date>
    </item>
    <item>
      <title>Re: customizing signatures question on AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183975#M77437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now I'm preparing the IPS Exam, and I have read some where that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"deny connection inline" will stop the connection totaly. But if the same user(IP Address) has many "deny connection inline", the IPS will say that there is a problem with this PC, and I'll not lose ressource and time to block each connection, and the the IPS sensor will block the Host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can tune the Signature to solve this issue, but this will not solve the main problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as Andy said, thier is a Sweep attack from these PCs. try to scan them with Anti-Virus, and anti-worm... because they are the source of this issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sweep is a "Network Reconnaissance Attack". Please take a look at this link for more information:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/5.1/configuration/guide/cli/cliSgEng.html#wp1048257" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/5.1/configuration/guide/cli/cliSgEng.html#wp1048257&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Reda&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:j.reda7@gmail.com"&gt;j.reda7@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Mar 2009 08:48:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/customizing-signatures-question-on-aip-ssm/m-p/1183975#M77437</guid>
      <dc:creator>rjaaouan</dc:creator>
      <dc:date>2009-03-26T08:48:35Z</dc:date>
    </item>
  </channel>
</rss>

