<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM configuration / blocking SMTP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914735#M85055</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may need to create an access-list permitting all traffic, and then apply the access-list to both interfaces in both directions (in and out).&lt;/P&gt;&lt;P&gt;This will ensure connections can go from the lower security zone to the higher as well as from the higher security zone to the lower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may also need to add icmp permit lines to permit icmp traffic through each interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Dec 2007 16:55:03 GMT</pubDate>
    <dc:creator>marcabal</dc:creator>
    <dc:date>2007-12-18T16:55:03Z</dc:date>
    <item>
      <title>AIP-SSM configuration / blocking SMTP</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914734#M85050</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  I need some help regarding a deployment of a IPS module on a ASA. I configured it in transparent mode, with the intention to only monitor the traffic going through the module. Otherwise after aplying the policy and put it in operation, it started blocking SMTP and ICMP traffic.  Here follows the configuration applied to it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map outside-class&lt;/P&gt;&lt;P&gt; match any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map outside-policy&lt;/P&gt;&lt;P&gt; class outside-class&lt;/P&gt;&lt;P&gt;  ips promiscuous fail-open&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy outside-policy interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything else I should consider to put this module just monitoring the traffic instead of having it denying any traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914734#M85050</guid>
      <dc:creator>carlos.allevato</dc:creator>
      <dc:date>2019-03-10T10:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration / blocking SMTP</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914735#M85055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may need to create an access-list permitting all traffic, and then apply the access-list to both interfaces in both directions (in and out).&lt;/P&gt;&lt;P&gt;This will ensure connections can go from the lower security zone to the higher as well as from the higher security zone to the lower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may also need to add icmp permit lines to permit icmp traffic through each interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2007 16:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914735#M85055</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2007-12-18T16:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration / blocking SMTP</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914736#M85060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marcabal for your reply. I'll proceed with the changes and let you know about the results. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2007 17:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-blocking-smtp/m-p/914736#M85060</guid>
      <dc:creator>carlos.allevato</dc:creator>
      <dc:date>2007-12-18T17:15:39Z</dc:date>
    </item>
  </channel>
</rss>

