<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS Based IPS --&amp;gt; No Alerts?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713064#M87017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your configuration seems ok. Can you please provide the following output:&lt;/P&gt;&lt;P&gt;1. show ip ips signature (as attachment)&lt;/P&gt;&lt;P&gt;2. What port scanning tool you used and how you used it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration has syslog/sdee enabled.If you have configured syslog server properly, the ips alerts will be sent to syslog server. So the question is whether IPS actually working and will be able to trigger events as expected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you know how to use metasploit, you can try use that to test it. "3Com 3CDaemon FTP Server Overflow" should trigger signature 3166/3173. (Use 'show ip ips signautre | in 3166' to check, it should show something like "3166:0     Y   Y     A     HIGH     0     1    0      0    0  FA  N 100 S190")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Apr 2007 18:33:07 GMT</pubDate>
    <dc:creator>ymzhang</dc:creator>
    <dc:date>2007-04-10T18:33:07Z</dc:date>
    <item>
      <title>IOS Based IPS --&gt; No Alerts??</title>
      <link>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713061#M87012</link>
      <description>&lt;P&gt;We are trying to setup a 2811 router to run IOS based IPS.  We followed all the procedures but we can't seem to get the system to send any alerts via syslog.  We have tried various port scanners with no luck.  Are we missing something?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713061#M87012</guid>
      <dc:creator>wmblake755</dc:creator>
      <dc:date>2019-03-10T10:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: IOS Based IPS --&gt; No Alerts??</title>
      <link>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713062#M87014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide more details about your IOS image and configuration that you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For latest IOS T-train image, you can try the getting started guide at &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6634/products_white_paper0900aecd805c4ea8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6634/products_white_paper0900aecd805c4ea8.shtml&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With more information, I can better answer your questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 18:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713062#M87014</guid>
      <dc:creator>ymzhang</dc:creator>
      <dc:date>2007-04-10T18:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: IOS Based IPS --&gt; No Alerts??</title>
      <link>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713063#M87016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the IOS version:&lt;/P&gt;&lt;P&gt;Cisco IOS Software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Experimental Version 12.4(20070215:163920) [jenneyc-V124_11_T1 107]&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2007 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Sun 11-Mar-07 12:16 by jenneyc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, this is the only message we got that might be considered a IDS alert.  But we don't get any alerts when we perform normal port scans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;188&amp;gt;2459: Apr 10 15:04:47.885: %IPS-4-SIGNATURE: Sig:2157 Subsig:1 Sev:75 [10.15.250.30:0 -&amp;gt; 10.11.100.61:0] RiskRating:63 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rtrwan-anf000#sho ip ips configuration &lt;/P&gt;&lt;P&gt;Configured Config Locations: flash:ips5/&lt;/P&gt;&lt;P&gt;Last signature default load time: 16:57:56 est Mar 14 2007&lt;/P&gt;&lt;P&gt;Last signature delta load time: 12:03:57 est Apr 10 2007&lt;/P&gt;&lt;P&gt;Last event action (SEAP) load time: -none-&lt;/P&gt;&lt;P&gt;General SEAP Config:&lt;/P&gt;&lt;P&gt; Global Deny Timeout: 3600 seconds&lt;/P&gt;&lt;P&gt; Global Overrides Status: Enabled&lt;/P&gt;&lt;P&gt; Global Filters Status: Enabled&lt;/P&gt;&lt;P&gt;IPS Auto Update is not currently configured&lt;/P&gt;&lt;P&gt;IPS fail closed is disabled&lt;/P&gt;&lt;P&gt;Fastpath ips is enabled&lt;/P&gt;&lt;P&gt;Quick run mode is enabled&lt;/P&gt;&lt;P&gt;Event notification through syslog is enabled&lt;/P&gt;&lt;P&gt;Event notification through SDEE is disabled&lt;/P&gt;&lt;P&gt;Total Active Signatures: 1090&lt;/P&gt;&lt;P&gt;Total Inactive Signatures: 899&lt;/P&gt;&lt;P&gt;IPS Rule Configuration&lt;/P&gt;&lt;P&gt; IPS name testips&lt;/P&gt;&lt;P&gt;IPS Category CLI Configuration:&lt;/P&gt;&lt;P&gt;    Category all: &lt;/P&gt;&lt;P&gt;        Retire: False&lt;/P&gt;&lt;P&gt;    Category viruses/worms/trojans all-viruses/worms/trojans: &lt;/P&gt;&lt;P&gt;        Retire: False&lt;/P&gt;&lt;P&gt;    Category p2p bittorrent: &lt;/P&gt;&lt;P&gt;        Retire: False&lt;/P&gt;&lt;P&gt;    Category p2p edonkey: &lt;/P&gt;&lt;P&gt;        Retire: False&lt;/P&gt;&lt;P&gt;    Category p2p kazaa: &lt;/P&gt;&lt;P&gt;        Retire: False&lt;/P&gt;&lt;P&gt;    Category reconnaissance: &lt;/P&gt;&lt;P&gt;        Retire: False Alert&lt;/P&gt;&lt;P&gt;Interface Configuration&lt;/P&gt;&lt;P&gt; Interface FastEthernet0/0.1&lt;/P&gt;&lt;P&gt;  Inbound IPS rule is testips&lt;/P&gt;&lt;P&gt;  Outgoing IPS rule is testips&lt;/P&gt;&lt;P&gt; Interface FastEthernet0/0.2&lt;/P&gt;&lt;P&gt;  Inbound IPS rule is testips&lt;/P&gt;&lt;P&gt;  Outgoing IPS rule is testips&lt;/P&gt;&lt;P&gt; Interface Serial0/0/0&lt;/P&gt;&lt;P&gt;  Inbound IPS rule is testips&lt;/P&gt;&lt;P&gt;  Outgoing IPS rule is testips&lt;/P&gt;&lt;P&gt; Interface Serial0/0/0.34&lt;/P&gt;&lt;P&gt;  Inbound IPS rule is testips&lt;/P&gt;&lt;P&gt;  Outgoing IPS rule is testips&lt;/P&gt;&lt;P&gt; Interface Serial0/0/0.35&lt;/P&gt;&lt;P&gt;  Inbound IPS rule is testips&lt;/P&gt;&lt;P&gt;  Outgoing IPS rule is testips&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 18:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713063#M87016</guid>
      <dc:creator>wmblake755</dc:creator>
      <dc:date>2007-04-10T18:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: IOS Based IPS --&gt; No Alerts??</title>
      <link>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713064#M87017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your configuration seems ok. Can you please provide the following output:&lt;/P&gt;&lt;P&gt;1. show ip ips signature (as attachment)&lt;/P&gt;&lt;P&gt;2. What port scanning tool you used and how you used it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration has syslog/sdee enabled.If you have configured syslog server properly, the ips alerts will be sent to syslog server. So the question is whether IPS actually working and will be able to trigger events as expected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you know how to use metasploit, you can try use that to test it. "3Com 3CDaemon FTP Server Overflow" should trigger signature 3166/3173. (Use 'show ip ips signautre | in 3166' to check, it should show something like "3166:0     Y   Y     A     HIGH     0     1    0      0    0  FA  N 100 S190")&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2007 18:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713064#M87017</guid>
      <dc:creator>ymzhang</dc:creator>
      <dc:date>2007-04-10T18:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: IOS Based IPS --&gt; No Alerts??</title>
      <link>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713065#M87018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try enabling sig 2004, ICMP Echo Request and then ping the interface of the router that has the IPS policy attached to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2007 18:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-based-ips-gt-no-alerts/m-p/713065#M87018</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2007-04-11T18:06:17Z</dc:date>
    </item>
  </channel>
</rss>

