<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need some clarification in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-some-clarification/m-p/557708#M89773</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In inline mode, the IPS (SSM-10) will bascially sits in the data path. All network traffic need to pass through the IPS to check/inspect and filter malicious traffic content like trojans, viruses, various types of network and application attacks and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short, IPS can/will intercept passing through network viruses, but not the one hovering outside the IPS, e.g viruses in end-user workstations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, in the event of viruses/worms outbreak where it tries to replicate itself all over the network, any passing through traffic (through IPS-SSM), e.g outbound to the internet, containing this malicious scripts will be stopped by IPS. However, for segments without IPS protection, no filtering can be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This combination allows you to handle viruses/worms/trojans issues both at the hosts level using host antivirus software,  and at the network level using IPS appliance (or ASA with SSM).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, Cisco partnered with TrendMicro to enhanced virus/malware protection in the new IPS 5.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps4077/products_data_sheet0900aecd801eeea5.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps4077/products_data_sheet0900aecd801eeea5.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 May 2006 15:18:07 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2006-05-30T15:18:07Z</dc:date>
    <item>
      <title>Need some clarification</title>
      <link>https://community.cisco.com/t5/network-security/need-some-clarification/m-p/557707#M89772</link>
      <description>&lt;P&gt;I have just installed ASA-5520 with SSM-10 module.  I have the IPS working and running in inline mode.  I need clarification on the anti virus features.  We currently use Symantec anti virus.  I dont understand how I can integrate the IPS and symantec to work hand in hand.  Also if an email virus breaks out and I activate or update the signature based on the virus, will the IPS catch it?  The IPS is installed inline with the internet connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any assistance.. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-some-clarification/m-p/557707#M89772</guid>
      <dc:creator>bvalentz</dc:creator>
      <dc:date>2019-03-10T10:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need some clarification</title>
      <link>https://community.cisco.com/t5/network-security/need-some-clarification/m-p/557708#M89773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In inline mode, the IPS (SSM-10) will bascially sits in the data path. All network traffic need to pass through the IPS to check/inspect and filter malicious traffic content like trojans, viruses, various types of network and application attacks and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In short, IPS can/will intercept passing through network viruses, but not the one hovering outside the IPS, e.g viruses in end-user workstations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, in the event of viruses/worms outbreak where it tries to replicate itself all over the network, any passing through traffic (through IPS-SSM), e.g outbound to the internet, containing this malicious scripts will be stopped by IPS. However, for segments without IPS protection, no filtering can be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This combination allows you to handle viruses/worms/trojans issues both at the hosts level using host antivirus software,  and at the network level using IPS appliance (or ASA with SSM).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, Cisco partnered with TrendMicro to enhanced virus/malware protection in the new IPS 5.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps4077/products_data_sheet0900aecd801eeea5.html" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps4077/products_data_sheet0900aecd801eeea5.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 May 2006 15:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-some-clarification/m-p/557708#M89773</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-05-30T15:18:07Z</dc:date>
    </item>
  </channel>
</rss>

