<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS IPS problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590950#M98731</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of the signatures you have enabled, are 1330-all subsigs and 1308 enabled? I have had similar issues like you described above and were related to these sigs. By default, they deny-packet and do not Produce-alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1308 is ttl evasion&lt;/P&gt;&lt;P&gt;1330 are normalizer sigs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My advice, if you have these sigs, is to add Produce-alert to these and then watch the events. See if these are firing. If so remove the deny actions on the subsigs that are dropping traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Apr 2006 04:50:25 GMT</pubDate>
    <dc:creator>mkirbyii</dc:creator>
    <dc:date>2006-04-12T04:50:25Z</dc:date>
    <item>
      <title>IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590944#M98716</link>
      <description>&lt;P&gt;I have a 3825 running 12.3(14)T4. On my serial port I have a T3/E3 card connecting to an MPLS cloud with about 40 sites and on my Gi0/1 port I have a SonicWall VPN concentrator connected to approx 200 sites. My servers are located off the Gi0/0 port. Typical throughput through the router averages about 2.0 MB through the Gi0/1 port and about 10 MB through the serial port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router has 256MB of memory installed and about 128MB available. I am loading 64 signatures with all the signatures set to alarm only. All other signatures have been deleted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After enabling IPS on the Gi0/0 outbound interface, everything works fine for several hours and then users begin complaining about a loss of connectivity. Users can&amp;#146;t connect to web sites nor can they log in to the AD and telnet and Citrix sessions get dropped and cannot be reestablished. The logs show no signatures being triggered and my session thresholds are well below max connection limits. Once IPS is disabled, all problems disappear instantly. This has happened on three different occasions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results from sho ip inspect conf (after IPS has been turned off) are as follows;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Session audit trail is enabled&lt;/P&gt;&lt;P&gt;Session alert is enabled&lt;/P&gt;&lt;P&gt;one-minute (sampling period) thresholds are [4500:100000000] connections&lt;/P&gt;&lt;P&gt;max-incomplete sessions thresholds are [4500:20000000]&lt;/P&gt;&lt;P&gt;max-incomplete tcp connections per host is 100000. Block-time 0 minute.&lt;/P&gt;&lt;P&gt;tcp synwait-time is 30 sec -- tcp finwait-time is 5 sec&lt;/P&gt;&lt;P&gt;tcp idle-time is 32400 sec -- udp idle-time is 30 sec&lt;/P&gt;&lt;P&gt;dns-timeout is 5 sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results from sho ip inspect stat (after IPS has been turned off) are as follows;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet inspection statistics [process switch:fast switch]&lt;/P&gt;&lt;P&gt;  tcp packets: [3669185:366719687]&lt;/P&gt;&lt;P&gt;  udp packets: [6797247:165723639]&lt;/P&gt;&lt;P&gt;   packets: [1441881:3408917]&lt;/P&gt;&lt;P&gt;   packets: [6801515:319778749]&lt;/P&gt;&lt;P&gt;Interfaces configured for inspection 0&lt;/P&gt;&lt;P&gt;Session creations since subsystem startup or last reset 511218&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [3489:380:5]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [0:0:0]&lt;/P&gt;&lt;P&gt;Last session created 2d06h&lt;/P&gt;&lt;P&gt;Last statistic reset 2d13h&lt;/P&gt;&lt;P&gt;Last session creation rate 1585&lt;/P&gt;&lt;P&gt;Last half-open session total 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Results from sho ip ips stat (after IPS has been turned off) are;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interfaces configured for ips 0&lt;/P&gt;&lt;P&gt;Session creations since subsystem startup or last reset 511218&lt;/P&gt;&lt;P&gt;Current session counts (estab/half-open/terminating) [3512:385:7]&lt;/P&gt;&lt;P&gt;Maxever session counts (estab/half-open/terminating) [0:0:0]&lt;/P&gt;&lt;P&gt;Last session created 2d06h&lt;/P&gt;&lt;P&gt;Last statistic reset 2d13h&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590944#M98716</guid>
      <dc:creator>edison9114</dc:creator>
      <dc:date>2019-03-10T09:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590945#M98721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mentioned AD logins, Citrix, and some HTTP requests fail.  Have you determined that these failures are all TCP based?  Note that the IOS IPS state tracking engines will not function properly with asymmetric routing or packets that get inspected twice by the same engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're not seeing any signatures firing, I would look to see what path and return path traffic takes to a certain host to ensure that they're the same.  Unexpected ACKs will likely get silently dropped by the state tracking engine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Feb 2006 15:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590945#M98721</guid>
      <dc:creator>Jeffrey Bollinger</dc:creator>
      <dc:date>2006-02-17T15:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590946#M98724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is only one path to these networks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Feb 2006 16:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590946#M98724</guid>
      <dc:creator>edison9114</dc:creator>
      <dc:date>2006-02-21T16:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590947#M98727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi. I have the similar problem(s)! Specifically with smtp and http requests; silently dropped. No log, no debug, nothing; just dropped! Checked only once, on outside intf in in direction. Was forced to turned ips off!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2006 08:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590947#M98727</guid>
      <dc:creator>efgeurobanka</dc:creator>
      <dc:date>2006-04-06T08:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590948#M98729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look at:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DTS # CSCsd07249 IOS FW/IPS enhancement: better handling of TCP out of order packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two ISR's at two sites, both  have the above issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try contacting  John Gawf (gawf) (&lt;A href="mailto:gawf@cisco.com"&gt;gawf@cisco.com&lt;/A&gt;), he may have a better answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Apr 2006 17:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590948#M98729</guid>
      <dc:creator>tdoran1</dc:creator>
      <dc:date>2006-04-08T17:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590949#M98730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Turns out to be related with asymmetric routing! &lt;/P&gt;&lt;P&gt;(Concept, regarding fw's/id's, poorly explained lately on site but causing HUGE problems!?)&lt;/P&gt;&lt;P&gt;Tanx.&lt;/P&gt;&lt;P&gt;Regards, Nikola&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Apr 2006 08:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590949#M98730</guid>
      <dc:creator>efgeurobanka</dc:creator>
      <dc:date>2006-04-10T08:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS problem</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590950#M98731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of the signatures you have enabled, are 1330-all subsigs and 1308 enabled? I have had similar issues like you described above and were related to these sigs. By default, they deny-packet and do not Produce-alert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1308 is ttl evasion&lt;/P&gt;&lt;P&gt;1330 are normalizer sigs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My advice, if you have these sigs, is to add Produce-alert to these and then watch the events. See if these are firing. If so remove the deny actions on the subsigs that are dropping traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Apr 2006 04:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-problem/m-p/590950#M98731</guid>
      <dc:creator>mkirbyii</dc:creator>
      <dc:date>2006-04-12T04:50:25Z</dc:date>
    </item>
  </channel>
</rss>

