<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem adding CSA external interface in IPS 6 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661858#M87752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your CSAMC is version 5.0 then can you please set the url to /csamc50/sdee-server and retry after enabling the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jan 2007 20:46:02 GMT</pubDate>
    <dc:creator>mkodali</dc:creator>
    <dc:date>2007-01-22T20:46:02Z</dc:date>
    <item>
      <title>Problem adding CSA external interface in IPS 6</title>
      <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661855#M87738</link>
      <description>&lt;P&gt;I configured my AIP-SSM sensor running IPS 6 to connect to the CSA MC, but I get a connection failure.  The sensor is showing the following error when trying to connect:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evError: eventId=1168311248090659938 severity=warning vendor=Cisco &lt;/P&gt;&lt;P&gt;  originator: &lt;/P&gt;&lt;P&gt;    hostId: os-ips&lt;/P&gt;&lt;P&gt;    appName: externalProductInterface&lt;/P&gt;&lt;P&gt;    appInstanceId: 317&lt;/P&gt;&lt;P&gt;  time: 2007/01/20 02:50:22 2007/01/19 20:50:22 GMT-06:00&lt;/P&gt;&lt;P&gt;  errorMessage: name=errNotAvailable Failure opening a subscription on the Management Center for Cisco Security Agents external interface at 1.1.1.1: Parse response found a different element when expecting the SOAP Envelope element&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661855#M87738</guid>
      <dc:creator>mcvosi</dc:creator>
      <dc:date>2019-03-10T10:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem adding CSA external interface in IPS 6</title>
      <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661856#M87741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please paste your config under service external-product-interface on the server? I am specifically looking for the url you have configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 16:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661856#M87741</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2007-01-22T16:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problem adding CSA external interface in IPS 6</title>
      <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661857#M87748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The interface is currently disabled, but I think you'll get the picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; cisco-security-agents-mc-settings (min: 0, max: 2, current: 1)&lt;/P&gt;&lt;P&gt;   -----------------------------------------------&lt;/P&gt;&lt;P&gt;      ip-address: 1.1.1.1&lt;/P&gt;&lt;P&gt;      -----------------------------------------------&lt;/P&gt;&lt;P&gt;         interface-type: extended-sdee &lt;PROTECTED&gt;&lt;/PROTECTED&gt;&lt;/P&gt;&lt;P&gt;         enabled: no default: yes&lt;/P&gt;&lt;P&gt;         url: /csamc/sdee-server &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;         port: 443 &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;         use-ssl&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;            always-yes: yes &lt;PROTECTED&gt;&lt;/PROTECTED&gt;&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;         username: adminuser&lt;/P&gt;&lt;P&gt;         password: &lt;HIDDEN&gt;&lt;/HIDDEN&gt;&lt;/P&gt;&lt;P&gt;         host-posture-settings&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;            enabled: yes default: yes&lt;/P&gt;&lt;P&gt;            allow-unreachable-postures: yes &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;            posture-acls (ordered min: 0, max: 10, current: 1 - 1 active, 0 inactive)&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;            ACTIVE list-contents&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;               NAME: 1-subnet&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;                  network-address: 192.168.1.0/24&lt;/P&gt;&lt;P&gt;                  action: permit&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;               -----------------------------------------------&lt;/P&gt;&lt;P&gt;            -----------------------------------------------&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;         watchlist-address-settings&lt;/P&gt;&lt;P&gt;         -----------------------------------------------&lt;/P&gt;&lt;P&gt;            enabled: yes &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;            manual-rr-increase: 25 &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;            session-rr-increase: 25 &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;            packet-rr-increase: 10 &lt;DEFAULTED&gt;&lt;/DEFAULTED&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 20:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661857#M87748</guid>
      <dc:creator>mcvosi</dc:creator>
      <dc:date>2007-01-22T20:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Problem adding CSA external interface in IPS 6</title>
      <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661858#M87752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your CSAMC is version 5.0 then can you please set the url to /csamc50/sdee-server and retry after enabling the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;Madhu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 20:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661858#M87752</guid>
      <dc:creator>mkodali</dc:creator>
      <dc:date>2007-01-22T20:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem adding CSA external interface in IPS 6</title>
      <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661859#M87753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This error indicates that the IPS is trying to establish communication with the CSA MC, and the CSA MC is returning an unexpected response. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple reasons you may be seeing this error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I noticed that the error message says that the IPS is configured to talk to a CSA MC with the IP address 1.1.1.1. Is this the correct IP address for the MC - I?m thinking that the message?s actual IP address was changed before posting for security reasons?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. For currently shipping and past versions of CSA MC, the CSA MC?s URL has to be configured in the IPS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* If the CSA MC is version 5.1 (most likely) then configured the URL to be: /csamc51/sdee-server&lt;/P&gt;&lt;P&gt;* If the CSA MC is version 5.0 then configured the URL to be: /csamc50/sdee-server&lt;/P&gt;&lt;P&gt;* Also, if the CSA MC is version 5.0 then be sure to apply the latest patches to the CSA MC since the unpatched versions had issues that caused communication failures and loss of data.&lt;/P&gt;&lt;P&gt;* Note: The next CSA MC release will eliminate the need to set the URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know whether this fixes the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 21:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661859#M87753</guid>
      <dc:creator>jplatzer</dc:creator>
      <dc:date>2007-01-22T21:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Problem adding CSA external interface in IPS 6</title>
      <link>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661860#M87754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah ha!  I missed that.  I'm using 5.1 and made the change; it now shows the connection as active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jan 2007 23:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-adding-csa-external-interface-in-ips-6/m-p/661860#M87754</guid>
      <dc:creator>mcvosi</dc:creator>
      <dc:date>2007-01-22T23:40:43Z</dc:date>
    </item>
  </channel>
</rss>

