<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS not detecting packets Entering &amp; Exiting Same Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637850#M87967</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This module describes how to configure the Cisco IOS Intrusion Prevention System (IPS), which helps to protect a customer's network from internal and external attacks and threats. Cisco IOS IPS restructures and replaces the existing Cisco IOS Intrusion Detection System (IDS). &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804453cf.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804453cf.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Jan 2007 14:16:56 GMT</pubDate>
    <dc:creator>smalkeric</dc:creator>
    <dc:date>2007-01-03T14:16:56Z</dc:date>
    <item>
      <title>IPS not detecting packets Entering &amp; Exiting Same Interface</title>
      <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637849#M87966</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Consider scenario :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host A---&amp;gt;Router B---&amp;gt;Router C &lt;/P&gt;&lt;P&gt;All are in the same subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router C also has an active interface on another subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I telnet from A to C (interface with ip address in another subnet),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I force traffic from A to C to pass through B, by setting static routes AND ** DISABLING IP REDIRECTS ***&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trafic flows from A to B IN through Fa0/0, and OUT again through Fa0/0 from B to C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ACL's (permit/log) that show this flow !!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have IPS enabled in/out on Fa0/0 on router B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, traffic flowing through Router B, which enters / exits the same interface, does not get picked up by IPS. (I trigger signatures)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal ?? Or am I missing something ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637849#M87966</guid>
      <dc:creator>shahedvoicerite</dc:creator>
      <dc:date>2019-03-10T10:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPS not detecting packets Entering &amp; Exiting Same Interface</title>
      <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637850#M87967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This module describes how to configure the Cisco IOS Intrusion Prevention System (IPS), which helps to protect a customer's network from internal and external attacks and threats. Cisco IOS IPS restructures and replaces the existing Cisco IOS Intrusion Detection System (IDS). &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804453cf.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6350/products_configuration_guide_chapter09186a00804453cf.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2007 14:16:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637850#M87967</guid>
      <dc:creator>smalkeric</dc:creator>
      <dc:date>2007-01-03T14:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPS not detecting packets Entering &amp; Exiting Same Interface</title>
      <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637851#M87968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't use the router IPS, but I'll give it a shot;-) I don't understand the network config. I'll try to redraw the network to see if I understand what you're saying:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host A&lt;/P&gt;&lt;P&gt;(NET1/IP1)&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;-------- (NET1/IP3) Router C (NET2/IP4)---&lt;/P&gt;&lt;P&gt;  |&lt;/P&gt;&lt;P&gt;(NET1/IP2)&lt;/P&gt;&lt;P&gt;Router B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host A uses Router B as its gateway to NET2 and since redirects are disabled on router B, all traffic from Host A to IP4 flows through router B.  If the diagram above is correct though, return traffic from router C will not be routed through Router B because the destination is on the same network as router C. How are you getting return traffic to flow through router B?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the following doc:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/application/pdf/en/us/guest/products/ps6634/c1244/cdccont_0900aecd80327257.pdf" target="_blank"&gt;http://www.cisco.com/application/pdf/en/us/guest/products/ps6634/c1244/cdccont_0900aecd80327257.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you're attempting to fire atomic signatures (single packet) then signatures should still fire anyway when inspected inbound.  If you're attempting to trigger a stateful signature then this would be a plausible explanation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jan 2007 17:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637851#M87968</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-01-03T17:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPS not detecting packets Entering &amp; Exiting Same Interface</title>
      <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637852#M87969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, your understanding of my network setup is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, return traffic does not go through B, but that is not the issue here, as I am trying to pickup STRING.TCP packets, which I believe as you mention are ATOMIC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e a telnet connection from A to C, and if I type the word "ATTACK" in the session :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router B should detect the string match  and drop the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The telnet packets I believe with the word "ATTACK" in this case wold go from A-&amp;gt;B inbound and B-&amp;gt;C outbound on the same FastEthernet port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the ips detection enabled both inbound and outbound on the Fa0/x port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jan 2007 11:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637852#M87969</guid>
      <dc:creator>shahedvoicerite</dc:creator>
      <dc:date>2007-01-04T11:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPS not detecting packets Entering &amp; Exiting Same Interface</title>
      <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637853#M87970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you gotten a trace to ensure that the characters you typed in actually resulted in the string ATTACK being sent in a single packet?  I think you'll find that this is not the case with telnet. My recollection is that each letter you type will be sent in a separate packet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jan 2007 14:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637853#M87970</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-01-04T14:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: IPS not detecting packets Entering &amp; Exiting Same Interface</title>
      <link>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637854#M87971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, I dont have a trace &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps you may be right about the "statefull"  versus "stateless" inspection problem going on in my case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to experiment, by setting a route map on the target router (C) and force traffic back through (B).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will also try other real "ATOMIC" tests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jan 2007 17:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-not-detecting-packets-entering-exiting-same-interface/m-p/637854#M87971</guid>
      <dc:creator>shahedvoicerite</dc:creator>
      <dc:date>2007-01-04T17:01:14Z</dc:date>
    </item>
  </channel>
</rss>

