<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS + CBAC problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-cbac-problem/m-p/852203#M85402</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Latest update: I found a bug for IPS 5.0 which I think is related to my problem, but I'm using IPS v4 signatures cause I need something like 12.4(15)T for IPS 5.0 signatures so I'm not sure that's my case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Headline  	 IPS5.0 : Signature statistics not displayed correctly&lt;/P&gt;&lt;P&gt;Product 	 IOS&lt;/P&gt;&lt;P&gt;Feature 	 OTHERS    Components 	Duplicate of 	 &lt;/P&gt;&lt;P&gt;Severity 	 3  Severity help 	Status 	 Resolved  Status help&lt;/P&gt;&lt;P&gt;First Found-in Version 	 12.4(10.8)T01   All affected versions 	First Fixed-in Version 	 12.4(12.15)T  Version help&lt;/P&gt;&lt;P&gt;Release Notes&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Symptoms:&lt;/P&gt;&lt;P&gt;This is a CLI display bug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;idConf/IPS 5.0 is configured on the IOS router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further Problem Description:&lt;/P&gt;&lt;P&gt;None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First thing that disturbs me - it's for 5.0, second thing - sounds like IPS statistics are not correct and in my case we are talking about CBAC statistics. Any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 03 Nov 2007 11:46:07 GMT</pubDate>
    <dc:creator>thegrave2000</dc:creator>
    <dc:date>2007-11-03T11:46:07Z</dc:date>
    <item>
      <title>IPS + CBAC problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-cbac-problem/m-p/852202#M85401</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a strange problem here - I activated IOS IPS on both internal and external interfaces in incoming direction and also had to run CBAC on the incoming direction of the external interface. The result of all these things is that the IPS is counting connections from the internal network and it's overwriting for some reason the statistics generated by CBAC, no matter that CBAC is enabled only on the external interface in incoming direction. I'm using 1812 router with 12.4(2)XA IOS. Searched for bugs in the Bug Toolkit, nothing showed up. Here are the outputs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; description WAN&lt;/P&gt;&lt;P&gt; bandwidth 6000&lt;/P&gt;&lt;P&gt; ip address xxx&lt;/P&gt;&lt;P&gt; ip access-group 102 in&lt;/P&gt;&lt;P&gt; ip verify unicast reverse-path&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect Web in&lt;/P&gt;&lt;P&gt; ip ips IPS in&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1452&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; service-policy output TrafficPolicy-OUT&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description LAN&lt;/P&gt;&lt;P&gt; bandwidth 6000&lt;/P&gt;&lt;P&gt; ip address xxx&lt;/P&gt;&lt;P&gt; ip access-group 100 in&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip nbar protocol-discovery&lt;/P&gt;&lt;P&gt; ip flow egress&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip ips IPS in&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; ip route-cache flow&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1452&lt;/P&gt;&lt;P&gt; service-policy output TrafficPolicy-IN&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name Web http alert on audit-trail off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ip inspect statistics &lt;/P&gt;&lt;P&gt;Packet inspection statistics [process switch:fast switch]&lt;/P&gt;&lt;P&gt;  tcp packets: [1315:117238]&lt;/P&gt;&lt;P&gt;  udp packets: [4681:36103]&lt;/P&gt;&lt;P&gt;   packets: [12:54]&lt;/P&gt;&lt;P&gt;   packets: [4747:119509]&lt;/P&gt;&lt;P&gt;  http packets: [0:829]&lt;/P&gt;&lt;P&gt;Interfaces configured for inspection 1&lt;/P&gt;&lt;P&gt;Session creations since subsystem startup or last reset 5024&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [739:78:0]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [815:96:8]&lt;/P&gt;&lt;P&gt;Last session created 00:00:00&lt;/P&gt;&lt;P&gt;Last statistic reset 00:10:08&lt;/P&gt;&lt;P&gt;Last session creation rate 487&lt;/P&gt;&lt;P&gt;Last half-open session total 78&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ip ips statistics     &lt;/P&gt;&lt;P&gt;Signature statistics [process switch:fast switch]&lt;/P&gt;&lt;P&gt;  signature 3050:0 packets checked: [4:0]&lt;/P&gt;&lt;P&gt;  signature 3173:0 packets checked: [18:0]&lt;/P&gt;&lt;P&gt;  signature 5477:2 packets checked: [0:3]&lt;/P&gt;&lt;P&gt;  signature 6253:0 packets checked: [0:159]&lt;/P&gt;&lt;P&gt;  signature 6064:0 packets checked: [1:0]&lt;/P&gt;&lt;P&gt;  signature 6056:0 packets checked: [1:0]&lt;/P&gt;&lt;P&gt;  signature 5170:1 packets checked: [0:11]&lt;/P&gt;&lt;P&gt;  signature 5322:1 packets checked: [0:2013]&lt;/P&gt;&lt;P&gt;  signature 4620:0 packets checked: [0:339822]&lt;/P&gt;&lt;P&gt;  signature 2157:1 packets checked: [1:37077]&lt;/P&gt;&lt;P&gt;  signature 2157:0 packets checked: [0:2]&lt;/P&gt;&lt;P&gt;  signature 1102:0 packets checked: [50:0]&lt;/P&gt;&lt;P&gt;Interfaces configured for ips 2&lt;/P&gt;&lt;P&gt;Session creations since subsystem startup or last reset 5153&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [744:72:0]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [815:96:8]&lt;/P&gt;&lt;P&gt;Last session created 00:00:00&lt;/P&gt;&lt;P&gt;Last statistic reset 00:10:26&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea about that? I'm pretty sure it's a bug but still can't prove it. As you can see I'm monitoring only http traffic entering the internal network with CBAC (they have a single web server which for sure cannot handle that much connections). I'll be glad if you can help but anyway if we can't find the truth behind this I'll simply disable the IPS on the internal interface and I think I'll get statistics pretty closer to the reality (I need them to tune CBAC TCP Intercept values). Besides that it's pretty nasty that you can't see separate statistics for each interface but anyway - I can live with that if I manage to get accurate statistics with limited security in that case. Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-cbac-problem/m-p/852202#M85401</guid>
      <dc:creator>thegrave2000</dc:creator>
      <dc:date>2019-03-10T10:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPS + CBAC problem</title>
      <link>https://community.cisco.com/t5/network-security/ips-cbac-problem/m-p/852203#M85402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Latest update: I found a bug for IPS 5.0 which I think is related to my problem, but I'm using IPS v4 signatures cause I need something like 12.4(15)T for IPS 5.0 signatures so I'm not sure that's my case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Headline  	 IPS5.0 : Signature statistics not displayed correctly&lt;/P&gt;&lt;P&gt;Product 	 IOS&lt;/P&gt;&lt;P&gt;Feature 	 OTHERS    Components 	Duplicate of 	 &lt;/P&gt;&lt;P&gt;Severity 	 3  Severity help 	Status 	 Resolved  Status help&lt;/P&gt;&lt;P&gt;First Found-in Version 	 12.4(10.8)T01   All affected versions 	First Fixed-in Version 	 12.4(12.15)T  Version help&lt;/P&gt;&lt;P&gt;Release Notes&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Symptoms:&lt;/P&gt;&lt;P&gt;This is a CLI display bug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;idConf/IPS 5.0 is configured on the IOS router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further Problem Description:&lt;/P&gt;&lt;P&gt;None&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First thing that disturbs me - it's for 5.0, second thing - sounds like IPS statistics are not correct and in my case we are talking about CBAC statistics. Any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Nov 2007 11:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-cbac-problem/m-p/852203#M85402</guid>
      <dc:creator>thegrave2000</dc:creator>
      <dc:date>2007-11-03T11:46:07Z</dc:date>
    </item>
  </channel>
</rss>

