<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Large file copy fails through 4240 sensor in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169839#M77760</link>
    <description>&lt;P&gt;Customer attempts to copy a large file from a server in an IPS protected vlan to a host in an IPS un-protected vlan and the copy fails if file is greater than about 2Gbytes in size. If the server is moved to the un-protected vlan the copy succeeds. There are no events on the IPS suggesting any blocking or other actions.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:29:45 GMT</pubDate>
    <dc:creator>paultribe</dc:creator>
    <dc:date>2019-03-10T11:29:45Z</dc:date>
    <item>
      <title>Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169839#M77760</link>
      <description>&lt;P&gt;Customer attempts to copy a large file from a server in an IPS protected vlan to a host in an IPS un-protected vlan and the copy fails if file is greater than about 2Gbytes in size. If the server is moved to the un-protected vlan the copy succeeds. There are no events on the IPS suggesting any blocking or other actions.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169839#M77760</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2019-03-10T11:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169840#M77763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When operating in-line the sensors will aotumaticly drop a packet flow that exceeds a minimum threat rating (I think it was 75% or 80%), you can look for them in the past hour with this CLI command:&lt;/P&gt;&lt;P&gt;sh ev al min-threat-rating 75 past 01:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2009 22:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169840#M77763</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-02-09T22:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169841#M77766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you point me to any documentation on this. I was checking the sensor's real time event log and did not see any events at the time of the file copy attempt.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2009 22:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169841#M77766</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2009-02-09T22:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169842#M77768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got my heads up on this topic from Marcabal on this forum. Correction, any risk rating over 90 will get dropped unless you option things differently.&lt;/P&gt;&lt;P&gt;Here's his post:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;topicID=.ee6e1fc&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc2a1d8" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Intrusion%20Prevention%20Systems/IDS&amp;amp;topicID=.ee6e1fc&amp;amp;fromOutline=&amp;amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cc2a1d8&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2009 23:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169842#M77768</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-02-09T23:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169843#M77771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure if I am missing  something here but if there are no events  with a RR in the high-risk category firing during the failed copy then what can I change. Apologies if I am msunderstanding something here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2009 23:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169843#M77771</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2009-02-09T23:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169844#M77774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have had a look at the links on the other forum and understand the concepts of the default event action override. I need to do some more testing to see if any signatures are firing when the file copy takes place, last time I'm sure I didn't see any.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2009 10:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169844#M77774</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2009-02-11T10:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169845#M77775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are not seeing any signatures firing then you might rule out any intertional packet dropping by the sensor. An overly busy inline IPS sensor can drop packets too. &lt;/P&gt;&lt;P&gt;What is your CPU utilization?&lt;/P&gt;&lt;P&gt;How much traffic are you trying to pass thru your sensor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2009 23:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169845#M77775</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-02-11T23:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169846#M77776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CPU does occasionly peak at 100% when transferring a large file but the copy often fails when the CPU is significantly lower. I know a 4240 has 300Mbit/s throughput but as I understood it traffic would still be serviced but would bypass the inspection process if exceeded, maybe a transition from inspection to non inspection causes the copy to fail like a tcp reset, I may try a sniffer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have TAC involved but like to try and utilise the knowledge of other expert users like yourself to try and rectify issues. Thanks for your help. If you have any other comments please let me know, I will certainly post my findings if you are interested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2009 23:40:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169846#M77776</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2009-02-11T23:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169847#M77777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While the 4240 is rated for 300 Mb/s we see packet loss starting at around 100 Mb/s in promiscious mode (and that's NOT full duplex, I'm adding both directions of transmission together). In my experience the "failover" only takes place once the sensor knows that the senor app has crashed, not necessarily that a sensor has been overloaded.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 00:04:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169847#M77777</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2009-02-12T00:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169848#M77778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There could be some normalizer engine events which can drop/modify traffic without firing an alert. Some of them seem to be on by default. Could you try enabling "produce alerts" on the normalizer signatures with deny or modify actions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another way would be to put an event action filter for the source or target (or both) and filter out all deny actions. In that way, you are telling the sensor do not block any traffic from or to certain IP address (based on how the filter is formed). I would use this filter to cover all signatures and sub signatures for the source/target in question.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 01:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169848#M77778</guid>
      <dc:creator>antonyabraham</dc:creator>
      <dc:date>2009-02-13T01:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169849#M77779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks - I found that a TCP normalizer sig was causing the issue, this is now resolved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Feb 2009 09:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169849#M77779</guid>
      <dc:creator>paultribe</dc:creator>
      <dc:date>2009-02-28T09:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169850#M77780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi paultribe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the same problem here. I found out that the IPS (in my case asa-ssm-10) is sometime reducing packet's TTL to as low as 5, which causes the packet being droppep by routers along the path.&lt;/P&gt;&lt;P&gt;Could you please inform me what sig you have changed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paulo Roque&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 21:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169850#M77780</guid>
      <dc:creator>pauloroque</dc:creator>
      <dc:date>2009-03-03T21:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169851#M77783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;I'd like the second the request for which normalizer sig is causing issues.  We have seen sporadic occurances of this situation and we are trying to get a handle on the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Scott Cothrell&lt;/P&gt;&lt;P&gt;IPS Engineering&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 22:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169851#M77783</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2009-03-03T22:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169852#M77786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make that a third request for the sig.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Mar 2009 14:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169852#M77786</guid>
      <dc:creator>bnidacoc</dc:creator>
      <dc:date>2009-03-05T14:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Large file copy fails through 4240 sensor</title>
      <link>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169853#M77788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are many TCP normalizer sigs that do not alert. I found the one that was affecting my customer by turning on alerting on all TCP normalizer sigs and emulating the issue (by attempting the file copy). I then checked the sensor logs and found the offending signature. It may not necessarily be the same signature for your issues so I would suggest you turn on the alerts and emulate the issues you have. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Mar 2009 08:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/large-file-copy-fails-through-4240-sensor/m-p/1169853#M77788</guid>
      <dc:creator>nowcommsupport</dc:creator>
      <dc:date>2009-03-08T08:47:26Z</dc:date>
    </item>
  </channel>
</rss>

