<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Ares with AIP-SSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-ares-with-aip-ssm/m-p/869940#M84736</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The AIP SSM can operate in one of two modes, such as: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inline mode&amp;#20;This mode places the AIP SSM directly in the traffic flow. You  must first pass through and be inspected by the AIP SSM before you can continue through the adaptive security appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This mode is the most secure because every packet is analyzed before it is allowed through. Also, the AIP SSM can implement a blocking policy on a packet-by-packet basis. But, this mode can affect throughput. Use the Inline keyword of the ips command in order to specify this mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Promiscuous mode&amp;#20;In this mode, a duplicate stream of traffic is sent to the AIP SSM. This mode is less secure. The SSM that operates in promiscuous mode instructs the adaptive security appliance to shun the traffic or resets a connection on the adaptive security appliance in order to block traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, while the AIP SSM analyzes the traffic, a small amount of traffic possibly passes through the adaptive security appliance before the AIP SSM can block it. Use the Promiscuous keyword of the ips command in order to specify this mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2008 23:12:26 GMT</pubDate>
    <dc:creator>bwilmoth</dc:creator>
    <dc:date>2008-02-07T23:12:26Z</dc:date>
    <item>
      <title>Block Ares with AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/block-ares-with-aip-ssm/m-p/869939#M84732</link>
      <description>&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  One of my costumers has the urgent need to block  one p2p application named ares. I searched in the p2p signature database and i found signatures for kazza, gnutella, imesh,etc , but didnt find any reference to this application.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Any ideas how can i block ares with an AIP-SSM ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ares-with-aip-ssm/m-p/869939#M84732</guid>
      <dc:creator>rretanag099</dc:creator>
      <dc:date>2019-03-10T10:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Block Ares with AIP-SSM</title>
      <link>https://community.cisco.com/t5/network-security/block-ares-with-aip-ssm/m-p/869940#M84736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The AIP SSM can operate in one of two modes, such as: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inline mode&amp;#20;This mode places the AIP SSM directly in the traffic flow. You  must first pass through and be inspected by the AIP SSM before you can continue through the adaptive security appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This mode is the most secure because every packet is analyzed before it is allowed through. Also, the AIP SSM can implement a blocking policy on a packet-by-packet basis. But, this mode can affect throughput. Use the Inline keyword of the ips command in order to specify this mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Promiscuous mode&amp;#20;In this mode, a duplicate stream of traffic is sent to the AIP SSM. This mode is less secure. The SSM that operates in promiscuous mode instructs the adaptive security appliance to shun the traffic or resets a connection on the adaptive security appliance in order to block traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, while the AIP SSM analyzes the traffic, a small amount of traffic possibly passes through the adaptive security appliance before the AIP SSM can block it. Use the Promiscuous keyword of the ips command in order to specify this mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2008 23:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ares-with-aip-ssm/m-p/869940#M84736</guid>
      <dc:creator>bwilmoth</dc:creator>
      <dc:date>2008-02-07T23:12:26Z</dc:date>
    </item>
  </channel>
</rss>

