<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS IPS troubleshooting in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753348#M86368</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am enabling the IPS functionality on a 3825 router with IOS 12.4(3d). The problem is that when I enable the IPS (inbound direction of the router's ethernet interface) I start having connectivity problems with some applications even with all the signatures on alert (not to drop traffic).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a debug or some troubleshooting that I can use in order to verify why the IPS is dropping some of the traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I have read that when you enable the IPS functionality the router automatically activates de inspect engine and in consequence it will drop out-of-order packets and half open connections, is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:40:02 GMT</pubDate>
    <dc:creator>vicente.madrigal</dc:creator>
    <dc:date>2019-03-10T10:40:02Z</dc:date>
    <item>
      <title>IOS IPS troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753348#M86368</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am enabling the IPS functionality on a 3825 router with IOS 12.4(3d). The problem is that when I enable the IPS (inbound direction of the router's ethernet interface) I start having connectivity problems with some applications even with all the signatures on alert (not to drop traffic).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a debug or some troubleshooting that I can use in order to verify why the IPS is dropping some of the traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I have read that when you enable the IPS functionality the router automatically activates de inspect engine and in consequence it will drop out-of-order packets and half open connections, is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:40:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753348#M86368</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2019-03-10T10:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753349#M86370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;most likely you are hitting the out-of-order issue. It is fixed in the latest T-train.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your question, you are right. When ips is enabled, it will activates the deep inspection engine which will drop out-of-order packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2007 04:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753349#M86370</guid>
      <dc:creator>ymzhang</dc:creator>
      <dc:date>2007-06-21T04:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753350#M86372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try the IOS upgrade to see if that helps me to solve the issue, by the way I am still looking for some debugs or troubleshooting commands that help me to verify that the IPS (and inspect engine) is dropping the packets. Do you know some commands or debugs that can help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2007 13:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753350#M86372</guid>
      <dc:creator>vicente.madrigal</dc:creator>
      <dc:date>2007-06-21T13:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS troubleshooting</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753351#M86373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. The module/doe that drops out-of-order packets belongs to the firewall session tracking function. If you use 'debug ip inspect detail' command, you should be able to find clue. Be careful not to use this command on your production network, this debug command will generate lots of messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2007 16:40:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-troubleshooting/m-p/753351#M86373</guid>
      <dc:creator>ymzhang</dc:creator>
      <dc:date>2007-06-21T16:40:18Z</dc:date>
    </item>
  </channel>
</rss>

