<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM inline mode Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-inline-mode-question/m-p/1131397#M79204</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config looks very similar to my working ASA confis. The only exception is your virtual sensor entries in the ASA and the IPS. If you don't need them they can be left out.&lt;/P&gt;&lt;P&gt;Assuming your config is correct, you can try opening up your access list to more traffic and see if you get events. You can turn on signature 2004 for ICMP echo replies if you want to stimulate some events for yourself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Aug 2008 14:58:31 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2008-08-06T14:58:31Z</dc:date>
    <item>
      <title>AIP-SSM inline mode Question</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-inline-mode-question/m-p/1131396#M79203</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an ASA 5520 with ips module . i installed it since 3 weeks. For the ips module , it is installed in inline mode.&lt;/P&gt;&lt;P&gt;Till now i didnot see any events appeared on the sensor.i configured it to scan http traffic from any source to the inside LAN subnet (10.1.0.0/16)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can i know that if the sensor is working properly or not?? and how ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the configuration on the ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_mpc extended permit tcp any 10.1.0.0 255.255.0.0 eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map outside-class&lt;/P&gt;&lt;P&gt; match access-list outside_mpc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map outside-policy1&lt;/P&gt;&lt;P&gt; class outside-class&lt;/P&gt;&lt;P&gt;  ips inline fail-open sensor vs0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy outside-policy1 interface outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please find the attached file for ips config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-inline-mode-question/m-p/1131396#M79203</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2019-03-10T11:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM inline mode Question</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-inline-mode-question/m-p/1131397#M79204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config looks very similar to my working ASA confis. The only exception is your virtual sensor entries in the ASA and the IPS. If you don't need them they can be left out.&lt;/P&gt;&lt;P&gt;Assuming your config is correct, you can try opening up your access list to more traffic and see if you get events. You can turn on signature 2004 for ICMP echo replies if you want to stimulate some events for yourself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 14:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-inline-mode-question/m-p/1131397#M79204</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-08-06T14:58:31Z</dc:date>
    </item>
  </channel>
</rss>

