<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDSM-2 Join windows domain problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167619#M77637</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, I have enabled produce alerts and will see if that give me any clue to what is wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Feb 2009 06:42:31 GMT</pubDate>
    <dc:creator>ola</dc:creator>
    <dc:date>2009-02-24T06:42:31Z</dc:date>
    <item>
      <title>IDSM-2 Join windows domain problem</title>
      <link>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167617#M77633</link>
      <description>&lt;P&gt;We are running a IDSM-2 module in a 6509 with vlan inline interface pairs.&lt;/P&gt;&lt;P&gt;Everything looks fine until we try to join a server to the 2003 domain.&lt;/P&gt;&lt;P&gt;I can't see the IPS dropping anything, but we get "network path not found" after entering the credentials for joining. If I set the IPS to bypass it works as it should. The software on the IPS is 6.2(1)E3 and all the servers are windows 2003. Greatful for any ideas of how to solve this.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167617#M77633</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2019-03-10T11:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM-2 Join windows domain problem</title>
      <link>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167618#M77635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This post from antonyabraham in another thread might help:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Replied by: antonyabraham - STATE FARM - Feb 12, 2009, 5:59pm PST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There could be some normalizer engine events which can drop/modify traffic without firing an alert. Some of them seem to be on by default. Could you try enabling "produce alerts" on the normalizer signatures with deny or modify actions? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another way would be to put an event action filter for the source or target (or both) and filter out all deny actions. In that way, you are telling the sensor do not block any traffic from or to certain IP address (based on how the filter is formed). I would use this filter to cover all signatures and sub signatures for the source/target in question. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167618#M77635</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-02-23T16:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM-2 Join windows domain problem</title>
      <link>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167619#M77637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, I have enabled produce alerts and will see if that give me any clue to what is wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 06:42:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167619#M77637</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2009-02-24T06:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM-2 Join windows domain problem</title>
      <link>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167620#M77639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, some traffic passed the sensor twice. So changing from virtual sensor mode to interface and vlan mode fixed the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2009 10:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-2-join-windows-domain-problem/m-p/1167620#M77639</guid>
      <dc:creator>ola</dc:creator>
      <dc:date>2009-03-09T10:18:26Z</dc:date>
    </item>
  </channel>
</rss>

