<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S246 caused sensor to stop passing traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545191#M92550</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first thing to do is log into the CLI and look at output from "show int" to see if any traffic is getting to the sensor.  Specifically look for Total Packets Received from the sensing interface.  Then look at "show stat virt" to see if any traffic is getting into the virtual sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is also possible you didn't wait long enough for the sig update to complete.  It could take a while to rebuild certain cache files even after reporting a successful update, and during that time the sensor would not be passing any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can't determine what is going on from the "show int" and "show stat virt", your best bet is to collect a "show tech" from both the ASA and the SSM module and open a TAC case so that the support engineers can look at it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Aug 2006 13:45:53 GMT</pubDate>
    <dc:creator>ssnapp</dc:creator>
    <dc:date>2006-08-24T13:45:53Z</dc:date>
    <item>
      <title>S246 caused sensor to stop passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545190#M92547</link>
      <description>&lt;P&gt;I applied S246 to AIP-SSM-10's this evening.  The AIP-SSM-10's are running 5.1(2).  The update said it was successful, but after it completed it caused all traffic going through the sensor to drop.  I've stopped sending traffic through the sensor from the ASA, but what's the next step?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ver tell me that MainApp and AnalysisEngine are Running.  What's the next step to troubleshoot?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545190#M92547</guid>
      <dc:creator>jshelmer</dc:creator>
      <dc:date>2019-03-10T10:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: S246 caused sensor to stop passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545191#M92550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first thing to do is log into the CLI and look at output from "show int" to see if any traffic is getting to the sensor.  Specifically look for Total Packets Received from the sensing interface.  Then look at "show stat virt" to see if any traffic is getting into the virtual sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is also possible you didn't wait long enough for the sig update to complete.  It could take a while to rebuild certain cache files even after reporting a successful update, and during that time the sensor would not be passing any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can't determine what is going on from the "show int" and "show stat virt", your best bet is to collect a "show tech" from both the ASA and the SSM module and open a TAC case so that the support engineers can look at it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2006 13:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545191#M92550</guid>
      <dc:creator>ssnapp</dc:creator>
      <dc:date>2006-08-24T13:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: S246 caused sensor to stop passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545192#M92556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the pointers.  It appears that traffic is getting to the sensor interface, but is getting marked as errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kssnchqips2# sh int gigabitEthernet0/1&lt;/P&gt;&lt;P&gt;MAC statistics from interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;   Interface function = Sensing interface&lt;/P&gt;&lt;P&gt;   Description =&lt;/P&gt;&lt;P&gt;   Media Type = backplane&lt;/P&gt;&lt;P&gt;   Missed Packet Percentage = 100&lt;/P&gt;&lt;P&gt;   Inline Mode = Unpaired&lt;/P&gt;&lt;P&gt;   Pair Status = N/A&lt;/P&gt;&lt;P&gt;   Link Status = Up&lt;/P&gt;&lt;P&gt;   Link Speed = Auto_1000&lt;/P&gt;&lt;P&gt;   Link Duplex = Auto_Full&lt;/P&gt;&lt;P&gt;   Total Packets Received = 1054106281&lt;/P&gt;&lt;P&gt;   Total Bytes Received = 1025753691656&lt;/P&gt;&lt;P&gt;   Total Multicast Packets Received = 0&lt;/P&gt;&lt;P&gt;   Total Broadcast Packets Received = 0&lt;/P&gt;&lt;P&gt;   Total Jumbo Packets Received = 0&lt;/P&gt;&lt;P&gt;   Total Undersize Packets Received = 0&lt;/P&gt;&lt;P&gt;   Total Receive Errors = 3934&lt;/P&gt;&lt;P&gt;   Total Receive FIFO Overruns = 57&lt;/P&gt;&lt;P&gt;   Total Packets Transmitted = 1054104717&lt;/P&gt;&lt;P&gt;   Total Bytes Transmitted = 1025753383141&lt;/P&gt;&lt;P&gt;   Total Multicast Packets Transmitted = 0&lt;/P&gt;&lt;P&gt;   Total Broadcast Packets Transmitted = 0&lt;/P&gt;&lt;P&gt;   Total Jumbo Packets Transmitted = 0&lt;/P&gt;&lt;P&gt;   Total Undersize Packets Transmitted = 0&lt;/P&gt;&lt;P&gt;   Total Transmit Errors = 0&lt;/P&gt;&lt;P&gt;   Total Transmit FIFO Overruns = 0&lt;/P&gt;&lt;P&gt;kssnchqips2#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Total Packets Received" counter is not incrementing.&lt;/P&gt;&lt;P&gt;But the "Total Bytes Received" counter is going up.&lt;/P&gt;&lt;P&gt;The "Total Receive Errors" also increment with each packet I send to the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2006 18:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545192#M92556</guid>
      <dc:creator>jshelmer</dc:creator>
      <dc:date>2006-08-24T18:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: S246 caused sensor to stop passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545193#M92562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only time I have seen something like this after a sig update was when the service account was used to ifconfig up the sensing interface in order to use tcpdump directly on the sensing interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please get a "show tech" from the sensor and open a TAC case.  Have the TAC engineer escalate this to IPS development so we can look at the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After getting a show tech, can you reset (reboot) the sensor to reload the interface drivers and see if this resolves it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2006 20:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545193#M92562</guid>
      <dc:creator>ssnapp</dc:creator>
      <dc:date>2006-08-24T20:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: S246 caused sensor to stop passing traffic</title>
      <link>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545194#M92564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "sh tech" has been attached to case 604241911.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Aug 2006 13:33:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/s246-caused-sensor-to-stop-passing-traffic/m-p/545194#M92564</guid>
      <dc:creator>jshelmer</dc:creator>
      <dc:date>2006-08-25T13:33:42Z</dc:date>
    </item>
  </channel>
</rss>

