<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MP2P Without IP address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380910#M97602</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What confusing me is that only this alert is triggering with out IP. All are ok..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Dec 2004 21:57:13 GMT</pubDate>
    <dc:creator>aohn</dc:creator>
    <dc:date>2004-12-20T21:57:13Z</dc:date>
    <item>
      <title>MP2P Without IP address</title>
      <link>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380908#M97600</link>
      <description>&lt;P&gt;Hi There&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an interesting question. Does anyone seen an alert on Cisco IDS 3.1(5)S82, MP2P Client Scan alerts with no info on SRC nor DEST IP addresses.?? There is positive scan happening since we detected 751 alert in 30 mins...&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:11:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380908#M97600</guid>
      <dc:creator>aohn</dc:creator>
      <dc:date>2019-03-10T09:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: MP2P Without IP address</title>
      <link>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380909#M97601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't seen an alert without an IP address. Here is a link on Configuring Automatic IP Logging and Configuring and Tuning Signatures that might be of some use.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mgt_ids/idsmc12/ug/ch05.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/rtrmgmt/cw2000/mgt_ids/idsmc12/ug/ch05.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2004 14:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380909#M97601</guid>
      <dc:creator>owillins</dc:creator>
      <dc:date>2004-12-20T14:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: MP2P Without IP address</title>
      <link>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380910#M97602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What confusing me is that only this alert is triggering with out IP. All are ok..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2004 21:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380910#M97602</guid>
      <dc:creator>aohn</dc:creator>
      <dc:date>2004-12-20T21:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: MP2P Without IP address</title>
      <link>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380911#M97603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the alert details to determine if this a Global Summary alert.&lt;/P&gt;&lt;P&gt;If it is, then that would explain what is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With a Global Summary the sensor will simply count the number of times the attack happens in a certain amount of time.  Because it counts attacks from any source address to any destination address it does not individually report them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this happens to be the case, then there are changes to the sensor that can be made to prevent the alert from going into Global Summary mode so that individual addresses will be reported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not seeing this a Global Summary, then there may be a bug that I am not aware of.&lt;/P&gt;&lt;P&gt;A copy of the alarm as it is recorded in the sensor's log file would be needed to debug further.&lt;/P&gt;&lt;P&gt;(Need the actual alarm as seen in the sensor log file, often screen captures from monitoring tools do not show all of the necessary alarm fields).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2004 22:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mp2p-without-ip-address/m-p/380911#M97603</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2004-12-20T22:34:29Z</dc:date>
    </item>
  </channel>
</rss>

