cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2430
Views
5
Helpful
3
Replies

IPS Test Attack Signatures

ms4561
Level 1
Level 1

I want to test my IPS triggering an inbound IPS Sig event. Can anyone advise if Cisco has test attack files available to download for this purpose?

Regards

3 Replies 3

jlimbo
Level 1
Level 1

We do not provide attack files, however if you simply want to test the signatures, some alerts which are easy to fire are:

2004-0 ICMP Echo Request

2000-0 ICMP Echo Reply

Please ensure you enable them, as they are disabled by default.

The signatures you advise do not exist in my .sdf (checked "sh ip ips sig"). only sigs in the 2000 cat(ICMP) are 2156, 2156:0,1,2.

Appreciate any further suggestions.

Use nessus or hping2 to test signatures. You will get tons of alarms when using nessus or

hping2 to simulate an attack on your network.

David

CCIE security

Review Cisco Networking for a $25 gift card