<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS unable to Block in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068860#M78988</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not able to configure firewall shun in cisco IPS, The option of blocking is disable in IPS for Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the attachement. Please help me out how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS is only able to block the routers but not firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Sep 2008 10:22:41 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2008-09-04T10:22:41Z</dc:date>
    <item>
      <title>IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068852#M78976</link>
      <description>&lt;P&gt;I have IPS 4255, I have made a Service HTTP signature to block metacafe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the block device for PIX Firewall. Signature triggers when i open &lt;A class="jive-link-custom" href="http://www.metacafe.com" target="_blank"&gt;www.metacafe.com&lt;/A&gt; i can see the user IP in active blocking hosts and also in IP logging but still i m not able to block/shun the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I select all actions in signature definiation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----Network Access Statistics-----&lt;/P&gt;&lt;P&gt;  section Current Configuration&lt;/P&gt;&lt;P&gt;      LogAllBlockEventsAndSensors true&lt;/P&gt;&lt;P&gt;      EnableNvramWrite false&lt;/P&gt;&lt;P&gt;      EnableAclLogging false&lt;/P&gt;&lt;P&gt;      AllowSensorBlock false&lt;/P&gt;&lt;P&gt;      BlockMaxEntries 250&lt;/P&gt;&lt;P&gt;      MaxDeviceInterfaces 250&lt;/P&gt;&lt;P&gt;    section NetDevice&lt;/P&gt;&lt;P&gt;        Type PIX&lt;/P&gt;&lt;P&gt;        IP 172.28.31.68&lt;/P&gt;&lt;P&gt;        NATAddr 0.0.0.0&lt;/P&gt;&lt;P&gt;        Communications ssh-3des&lt;/P&gt;&lt;P&gt;        ResponseCapabilities block&lt;/P&gt;&lt;P&gt;    section NeverBlock&lt;/P&gt;&lt;P&gt;        IP 172.28.92.72&lt;/P&gt;&lt;P&gt;        IP 172.28.31.0&lt;/P&gt;&lt;P&gt;        IP 192.168.249.0&lt;/P&gt;&lt;P&gt;        IP 192.168.250.0&lt;/P&gt;&lt;P&gt;  section State&lt;/P&gt;&lt;P&gt;      BlockEnable true&lt;/P&gt;&lt;P&gt;    section NetDevice&lt;/P&gt;&lt;P&gt;        IP 172.28.31.68&lt;/P&gt;&lt;P&gt;        AclSupport Does not use ACLs&lt;/P&gt;&lt;P&gt;        Version 0&lt;/P&gt;&lt;P&gt;        State Inactive&lt;/P&gt;&lt;P&gt;        Firewall-type PIX&lt;/P&gt;&lt;P&gt;Please help me out what i m missing.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068852#M78976</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-10T11:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068853#M78977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you allow the sensor IP on the PIX for SSH?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh &lt;SENSOR-IP&gt; interface ?&lt;/SENSOR-IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you add the PIX as a trusted host on the sensor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the SSH even working on the PIX from other hosts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Double check your PIX credentials. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Login to PIX and issue a 'who' command to see if the IPS is logged in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2008 10:18:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068853#M78977</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-28T10:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068854#M78978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My firewall is configured for AAA. I gave the same credential in IPS blocking devices that i m using for myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSH is allowed on firewall for any IP.&lt;/P&gt;&lt;P&gt;IPS also has any ip to trusted hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS allowed host&lt;/P&gt;&lt;P&gt;telnet-option enabled&lt;/P&gt;&lt;P&gt;access-list 172.28.0.0/16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPs only able to push access-list on router but not able to shun pix firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2008 13:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068854#M78978</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-08-28T13:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068855#M78979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"IPS also has any ip to trusted hosts. " this is not possible you have to do it manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am talking about adding the SSH key of the PIX  in the IPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/6.0/command/reference/crCmds.html#wp553621" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/6.0/command/reference/crCmds.html#wp553621&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go to the IPS CLI and issue the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh host-key &lt;PUT-PIXIP-HERE&gt;&lt;/PUT-PIXIP-HERE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2008 13:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068855#M78979</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-28T13:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068856#M78980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried even this, but still the problem is there, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am attaching the screen shot, I am not able to configure block action, the tab is not highlighted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why it is so, may be this is the reason.?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2008 16:00:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068856#M78980</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-08-28T16:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068857#M78981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you enabled blocking globally?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Blocking &amp;gt;&amp;gt; Blocking Properties&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2008 17:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068857#M78981</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-28T17:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068858#M78983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes blocking is globally enabled. IPs able to write access-list on routers but not able to shun pix firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Aug 2008 20:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068858#M78983</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-08-28T20:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068859#M78985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please enable the block action on any common signature like ICMP echo (2004) and then check the event log of the IPS. It will tell you why the shun is failing. Also login to the firewall and do a 'who' command during this test to see if the IPS logs in. Do 'terminal monitor' and 'logging monitor 6' on firewall to see any denies etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 17:54:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068859#M78985</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-29T17:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068860#M78988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not able to configure firewall shun in cisco IPS, The option of blocking is disable in IPS for Firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the attachement. Please help me out how to do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS is only able to block the routers but not firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 10:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068860#M78988</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-09-04T10:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068861#M78991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When i view the log on IPS, it shows me the following error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall type unknow. Please see the screen shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly when i did who on firewall i didnt see anybody connected. Firewall logging is also not showing that IPS IP address is block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Sep 2008 10:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068861#M78991</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-09-04T10:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPS unable to Block</title>
      <link>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068862#M78995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can anybody help me out in this matter. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Sep 2008 10:58:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-unable-to-block/m-p/1068862#M78995</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-09-07T10:58:32Z</dc:date>
    </item>
  </channel>
</rss>

