01-18-2010 07:27 AM - edited 03-10-2019 04:51 AM
Mates,
we have an Cisco ASA with an SSM-20 Module running in our network. I tried to test the IPS module with a NMAP version 5.
It detects TCP connects scan and SYN scans. FIN, NULL and XMAS tree Scans as well as OS Guessing attempts are not detected.
Any ideas?
Cheers
Alex
02-07-2010 10:26 AM
Some of those scans are designed to evade detection devices, however are you running the latest signature on your AIP?
Regards
Farrukh
02-10-2010 07:48 AM
Hello Farrukh,
thanks for your reply, yes the ips gets its update by an automated update procedure. You think its normal that the IPS is not detecting OS guessing attempts? But for what is then the Signature NMAP OS Fingerprint good.
https://intellishield.cisco.com/security/alertmanager/ipsSignature?signatureId=3046&signatureSubId=0
Cheers
Alex
02-10-2010 10:57 AM
Yes this is true, not all NMAP scan types are detected by the Cisco IPS. I've seen it on our network too.
Regards
Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide