02-02-2012 12:31 AM - edited 03-10-2019 05:36 AM
Dear all i have an issue while configuring Cisco IPS4255 in lab,
when i configure the two interfaces of device as inline interface pair mode and create an attack using any signature such as 2004 , 11020, 3401 , the actions of signature i.e. deny packet inlinle, or deny connection inline are not working mean that these two options when selected dnt block the packets or connections of specified traffic , although the events show that deny packet inline and deny connection inline are getting true value.
Only option that works from the list is ' deny attacker inline' for any of the signature.
Is that because of licensing issue because my device doe not have valid license installed in it right now or i am not configuring the device properly.
Thx in advance for kind help
asif
Solved! Go to Solution.
02-02-2012 08:43 AM
The lack of a current license will not prevent proper sensor operation. It should still block traffic as you have configured.
The only limitation of an unlicensed sensor is you can not install signature updates (you can only install software updates).
- Bob
02-02-2012 08:43 AM
The lack of a current license will not prevent proper sensor operation. It should still block traffic as you have configured.
The only limitation of an unlicensed sensor is you can not install signature updates (you can only install software updates).
- Bob
02-08-2012 09:01 PM
thank you bob for your answer, it is working fine now , you were right, issue was that i did configured event action overriding in IPS and just selected "Deny attacker inline" option, thats why every signature's action was getting override. It is working without license.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide