<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS features in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-features/m-p/429066#M90738</link>
    <description>&lt;P&gt;Hi, I just got my ASA 5520 firewall with (ASA SSM-20 module), and would be grateful if anyone could inform me about these questions concerning IPS features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. in the signature configuration of aip-ssm most signatures are set with action &amp;#147;produce alert&amp;#148; even virus, why? I suppose that I have to go trough all signatures and set the action to, for example &amp;#147;deny packet inline&amp;#148; for virus.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. With an update of the signatures will the changes be lost or unchanged?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. will the configuration example below include all the signature features and at the same time protect against vpn traffic (outside-&amp;gt;inside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list IPS permit ip any any&lt;/P&gt;&lt;P&gt;access-group IPS in interface inside&lt;/P&gt;&lt;P&gt;access-group IPS in interface outside&lt;/P&gt;&lt;P&gt;class-map my-ips-class&lt;/P&gt;&lt;P&gt;match access-list IPS&lt;/P&gt;&lt;P&gt;policy-map my-ids-policy&lt;/P&gt;&lt;P&gt;class my-ips-class&lt;/P&gt;&lt;P&gt;ips promiscuous fail-close&lt;/P&gt;&lt;P&gt;service-policy my-ids-policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:50:13 GMT</pubDate>
    <dc:creator>hanna.petersson</dc:creator>
    <dc:date>2019-03-10T09:50:13Z</dc:date>
    <item>
      <title>IPS features</title>
      <link>https://community.cisco.com/t5/network-security/ips-features/m-p/429066#M90738</link>
      <description>&lt;P&gt;Hi, I just got my ASA 5520 firewall with (ASA SSM-20 module), and would be grateful if anyone could inform me about these questions concerning IPS features.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. in the signature configuration of aip-ssm most signatures are set with action &amp;#147;produce alert&amp;#148; even virus, why? I suppose that I have to go trough all signatures and set the action to, for example &amp;#147;deny packet inline&amp;#148; for virus.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. With an update of the signatures will the changes be lost or unchanged?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. will the configuration example below include all the signature features and at the same time protect against vpn traffic (outside-&amp;gt;inside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list IPS permit ip any any&lt;/P&gt;&lt;P&gt;access-group IPS in interface inside&lt;/P&gt;&lt;P&gt;access-group IPS in interface outside&lt;/P&gt;&lt;P&gt;class-map my-ips-class&lt;/P&gt;&lt;P&gt;match access-list IPS&lt;/P&gt;&lt;P&gt;policy-map my-ids-policy&lt;/P&gt;&lt;P&gt;class my-ips-class&lt;/P&gt;&lt;P&gt;ips promiscuous fail-close&lt;/P&gt;&lt;P&gt;service-policy my-ids-policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-features/m-p/429066#M90738</guid>
      <dc:creator>hanna.petersson</dc:creator>
      <dc:date>2019-03-10T09:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPS features</title>
      <link>https://community.cisco.com/t5/network-security/ips-features/m-p/429067#M90739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Normally, the action "produce-alert" writes the event to the Event Store as an alert. In this scenario,  a virus signature is set with action "produce-alert".So, when a virus matching with the configured signature is detected by the sensor, it looks at the corresponding signature action and performs accordingly.  In this case, the signature action is " produce-alert", this means that the sensor writes this virus event to the event store as an alert.This will help in identifying the virus at its arrival and also produces alert so that precautionary steps can be taken.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any further doubts, the following document will completely clarify all your doubts:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df97.html#wp1040176" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008055df97.html#wp1040176&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2006 15:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-features/m-p/429067#M90739</guid>
      <dc:creator>wong34539</dc:creator>
      <dc:date>2006-01-17T15:57:17Z</dc:date>
    </item>
  </channel>
</rss>

