cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
730
Views
0
Helpful
1
Replies

IPS loses IP Mangement comms.

Martin Bosch
Level 5
Level 5

I have picked up an issue where every few hours my Cisco IPS Manger Express 7.1.1 will stop reporting events. When I investigate I see that my IPS what looks like has lost IP communications on the management interface.
My setup is a Cisco 3945 with an NME-IP module.
If I connect to the router and view the status it seems fine
Service Module is Cisco IDS-Sensor2/0
Service Module supports session via TTY line 131
Service Module is in Steady state
Service Module heartbeat-reset is enabled
Getting status from the Service Module, please wait..

Cisco Systems Intrusion Prevention System Network Module
  Software version:  7.0(2)E4
  Model:             NME-IPS
  Memory:            443504 KB
  Mgmt IP addr:      <removed>
  Mgmt web ports:    443
  Mgmt TLS enabled:  true

If I session back to the IPS via the routers cli ie service-module interface and try to ping anything back to my manage interface it times out. Now this is where it does not make sense. 
I log back to the router and reset the service-module. Then everything will work as it’s supposed to for a few hours.

My IPS management port is configured for

service interface

physical-interfaces Management0/1

duplex full

speed 100

The switch has been set the same.

I have picked up every now and again  input errors / crc errors.

The cable has been replaced. Another cable did the same. Both cables tested with flukes cable tester.

Tried to move the IPS management to a Gig interface as well as to another switch all together. Still seem to pick up this issue.

Just strange it will work fine for hours with out any issue / input / crc errors then it "drops"

Any ideas?

1 Reply 1

Martin Bosch
Level 5
Level 5

FYI

OK This is what I have done.

The NME-IPS management forced to 100/full

The switch after trying two switches (100 meg ports) with the config first auto then forced.

Still had the same issue.

However, I have moved it to a gig port - auto. And it been stable for the last 23 hours.

Review Cisco Networking for a $25 gift card