<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS - Startup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087182#M78190</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you share the sample configuaration ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Dec 2008 10:54:51 GMT</pubDate>
    <dc:creator>CSCO10320953</dc:creator>
    <dc:date>2008-12-30T10:54:51Z</dc:date>
    <item>
      <title>IPS - Startup</title>
      <link>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087179#M78180</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have recently purchased an AIP-SSM-10 module for our ASA5520.  I have installed the module run through the initial configuration and updated the software / signatures to the latest version via the ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am about to run through the following...Send Network Traffic from the ASA to the AIP SSM...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807335ca.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807335ca.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but would like to know a little more about what will happen once traffic is redirected, my qusetions are as follows...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the IPS start blocking traffic by default? or does it just report?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we enbale the IPS so that its just reports on what action would have been taken?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally we would like to run traffic through the IPS for a week or so without any blocking, so we can analyze it to reduce false positives.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any documentation expalaining this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all you help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087179#M78180</guid>
      <dc:creator>AxiomConsulting</dc:creator>
      <dc:date>2019-03-10T11:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Startup</title>
      <link>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087180#M78184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default actions of an in-line IPS is to drop the packets that match signatures set to drop. There are a few signatures that are not set to generate an alert when dropped. &lt;/P&gt;&lt;P&gt;I think you want to start with your sensor in promiscious mode, not in-line. Then you can watch what signatures fire that would be dropped in an in-line mode.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2008 22:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087180#M78184</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-12-04T22:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Startup</title>
      <link>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087181#M78189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that, I ended up throwing caution to the wind and processing all traffic (inline) all looks good so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using IPS Event Viewer for 'Real Time' analysis and reporting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any other recommendations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 10:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087181#M78189</guid>
      <dc:creator>AxiomConsulting</dc:creator>
      <dc:date>2008-12-09T10:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - Startup</title>
      <link>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087182#M78190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you share the sample configuaration ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Dec 2008 10:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-startup/m-p/1087182#M78190</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-12-30T10:54:51Z</dc:date>
    </item>
  </channel>
</rss>

