<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS - tcp segment overwrite - WAY TOO MANY in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735115#M86405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are on a 4250, 4250XL or a IDSM-2 then you might be hitting CSCsg23774.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsg23774" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsg23774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The defect was corrected in 6.0(1).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jun 2007 18:21:24 GMT</pubDate>
    <dc:creator>mlhall</dc:creator>
    <dc:date>2007-06-19T18:21:24Z</dc:date>
    <item>
      <title>IPS - tcp segment overwrite - WAY TOO MANY</title>
      <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735111#M86397</link>
      <description>&lt;P&gt;We had consultants install our new ips.  They recommended plugging into a switch connecting our firewall to our internet router.  We have a bunch of VPN tunnels terminating at our ASA firewall from our remote offices.  When I check the logs on the IPS, there are tons of alerts for "tcp segment overwrite" and alot of them come from the vpn sites.  My question is, what can I do to alleviate some of these messages?  I can't believe that we are being attacked this much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To clarify our installation, we have 2 switches, one in each of our two buildings, and they are connected via fibre.  We have a ASA in each building and they are setup for redundancy.  Our IPS has only one interface plugged into the same vlan the hosts the firewall and the internet router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735111#M86397</guid>
      <dc:creator>tverhoeven</dc:creator>
      <dc:date>2019-03-10T10:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - tcp segment overwrite - WAY TOO MANY</title>
      <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735112#M86400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this is in an inline scenario the offending packets are dropped by default.  To investigate it further I check to see what other alerts are triggering for the offending hosts.  This will give you more information to ascertain what these hosts are really doing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 00:29:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735112#M86400</guid>
      <dc:creator>jlimbo</dc:creator>
      <dc:date>2007-06-19T00:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - tcp segment overwrite - WAY TOO MANY</title>
      <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735113#M86402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is not inline...only have one interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked through and handful of the logs and I have ip's from my internal network and from remote vpn connections.  Is there a way to search thru the log to find multiple occurrences of the same host???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 00:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735113#M86402</guid>
      <dc:creator>tverhoeven</dc:creator>
      <dc:date>2007-06-19T00:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - tcp segment overwrite - WAY TOO MANY</title>
      <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735114#M86403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have the same issue.   we see them too much in "normal" traffic for the sig to be useful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 12:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735114#M86403</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-06-19T12:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - tcp segment overwrite - WAY TOO MANY</title>
      <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735115#M86405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are on a 4250, 4250XL or a IDSM-2 then you might be hitting CSCsg23774.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsg23774" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsg23774&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The defect was corrected in 6.0(1).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2007 18:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735115#M86405</guid>
      <dc:creator>mlhall</dc:creator>
      <dc:date>2007-06-19T18:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPS - tcp segment overwrite - WAY TOO MANY</title>
      <link>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735116#M86406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks man...that seemed to do the trick.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good thing I did not do that upgrade last week when I was studying for the IPS exam.  Whole new interface would have thrown me off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2007 14:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-tcp-segment-overwrite-way-too-many/m-p/735116#M86406</guid>
      <dc:creator>tverhoeven</dc:creator>
      <dc:date>2007-06-20T14:26:38Z</dc:date>
    </item>
  </channel>
</rss>

