<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDS and two switches in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ids-and-two-switches/m-p/644208#M92417</link>
    <description>&lt;P&gt;I have an IDS "listening in" on two switches. Problems begin when a host connected to switch1 talks to another host connected to switch2. Apparently I can see the packets twice (the only difference is TTL decreased by one). To make it more interesting SigID:1300-0 Sig:TCP Segment Overwrite starts firing.  &lt;/P&gt;&lt;P&gt;Any suggestions greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:13:04 GMT</pubDate>
    <dc:creator>apolkosnik</dc:creator>
    <dc:date>2019-03-10T10:13:04Z</dc:date>
    <item>
      <title>IDS and two switches</title>
      <link>https://community.cisco.com/t5/network-security/ids-and-two-switches/m-p/644208#M92417</link>
      <description>&lt;P&gt;I have an IDS "listening in" on two switches. Problems begin when a host connected to switch1 talks to another host connected to switch2. Apparently I can see the packets twice (the only difference is TTL decreased by one). To make it more interesting SigID:1300-0 Sig:TCP Segment Overwrite starts firing.  &lt;/P&gt;&lt;P&gt;Any suggestions greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-and-two-switches/m-p/644208#M92417</guid>
      <dc:creator>apolkosnik</dc:creator>
      <dc:date>2019-03-10T10:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: IDS and two switches</title>
      <link>https://community.cisco.com/t5/network-security/ids-and-two-switches/m-p/644209#M92418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This signature 1300 will only fire when the data in the stream is attempting to be overwritten with different data than what was previously seen at that sequence offset.  The issue is due to Networking stacks based on BSD4.2 implementations might use a older method of sending TCP keepalives. The IDS flags this as a TCP overwrite and fires signature 1300. The resolution is to Upgrade to sensor v5.0 where this trigger will not cause an alarm to fire.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Sep 2006 19:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ids-and-two-switches/m-p/644209#M92418</guid>
      <dc:creator>vmoopeung</dc:creator>
      <dc:date>2006-09-18T19:04:05Z</dc:date>
    </item>
  </channel>
</rss>

