<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Inspecting traffic one way in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038201#M78262</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure AIP-SSM to inspect traffic in inline or promiscuous mode and in fail-open or fail-over mode.On the adaptive security appliance, to identify traffic to be diverted to and inspected by AIP-SSM: &lt;/P&gt;&lt;P&gt;1. Create or use an existing ACL. &lt;/P&gt;&lt;P&gt;2. Use the class-map command to define the IPS traffic class. &lt;/P&gt;&lt;P&gt;3. Use the policy-map command to create an IPS policy map by associating the traffic class with one or more actions. &lt;/P&gt;&lt;P&gt;4. Use the service-policy command to create an IPS security policy by associating the policy map with one or more interfaces.The AIP SSM runs advanced IPS software that provides proactive, full-featured intrusion prevention services to stop malicious traffic, including worms and network viruses, before they can affect your network. This section includes the following topics: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_ssm.html#wp1046877" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_ssm.html#wp1046877&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ssm.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ssm.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Dec 2008 17:28:54 GMT</pubDate>
    <dc:creator>sadbulali</dc:creator>
    <dc:date>2008-12-02T17:28:54Z</dc:date>
    <item>
      <title>Inspecting traffic one way</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038200#M78260</link>
      <description>&lt;P&gt;Hi, is there a way on IPS v6.1 to only inspect traffic in one direction? Implementation is pair interfaces. Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:23:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038200#M78260</guid>
      <dc:creator>brobinson</dc:creator>
      <dc:date>2019-03-10T11:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Inspecting traffic one way</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038201#M78262</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure AIP-SSM to inspect traffic in inline or promiscuous mode and in fail-open or fail-over mode.On the adaptive security appliance, to identify traffic to be diverted to and inspected by AIP-SSM: &lt;/P&gt;&lt;P&gt;1. Create or use an existing ACL. &lt;/P&gt;&lt;P&gt;2. Use the class-map command to define the IPS traffic class. &lt;/P&gt;&lt;P&gt;3. Use the policy-map command to create an IPS policy map by associating the traffic class with one or more actions. &lt;/P&gt;&lt;P&gt;4. Use the service-policy command to create an IPS security policy by associating the policy map with one or more interfaces.The AIP SSM runs advanced IPS software that provides proactive, full-featured intrusion prevention services to stop malicious traffic, including worms and network viruses, before they can affect your network. This section includes the following topics: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_ssm.html#wp1046877" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_ssm.html#wp1046877&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ssm.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/ssm.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Dec 2008 17:28:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038201#M78262</guid>
      <dc:creator>sadbulali</dc:creator>
      <dc:date>2008-12-02T17:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: Inspecting traffic one way</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038202#M78264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a setting for "loose" TCP processing that is supposed to allow the sensor to watch only half of a TCP conversation, but we found it didn'twork very well and CPU unexpectedly increased significantly as a result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Dec 2008 20:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038202#M78264</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-12-02T20:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Inspecting traffic one way</title>
      <link>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038203#M78265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all the replies! Good info. : )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2008 23:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inspecting-traffic-one-way/m-p/1038203#M78265</guid>
      <dc:creator>brobinson</dc:creator>
      <dc:date>2008-12-04T23:27:50Z</dc:date>
    </item>
  </channel>
</rss>

