Questions of pre-installation on IPS on Cisco ASA Cluster

Hello

I'm looking for some configuration directives and IPS.

I have a Cisco ASA Cluster with an IPS Module and I would like to know the best way to go about setting it up.

We have a customer who requires their web servers to be protected with the IPS Module.  I have the following questions:

1. is it possible to install the IPS in learning mode type to see what kind of traffic is hitting?

2. can you syslog alerts?

3. is it possible to use snmp around alert also interrupts?

4. If you put it in promiscuous mode (SDI) what it means when you receive an alert about a possible attack, an administrator must log on the

Firewall and block traffic if they choose to do so?  Is it possible for an administrator to block traffic (or leave if his)

a false positive in IPS) without having to connect to the ASDM?  If you have a scenario where you don't want to give users access to

the firewall, what is the best way to go about this?

5. is it possible to set up an alert that if this is a DDOS email alert, if it's a handshake of split then just syslog alert?

6. I'm afraid that if I put it with a profile he can start blocking valid traffic.  What is the best way to start with IPS to protect

a server?

7 if its possible to syslog, what kind of detail is the capture of syslog?  Need name attack, etc.?

A lot of questions!  I hope someone can help

Thanks a mill

1. is it possible to install the IPS in learning mode type to see what kind of traffic is hitting?

Yes. There are several ways to do this, but the easiest way is to put the sensor in promiscuous mode (in the config of the ASA)

2. can you syslog alerts?

N ° the cisco IPS OS doesn't support syslog.

3. is it possible to use snmp around alert also interrupts?

Yes. But you must set the 'action' on each signature that you want to send a trap.

4. If you put it in promiscuous mode (SDI) what it means when you receive an alert about a possible attack, an administrator must log on the

Firewall and block traffic if they choose to do so?  Is it possible for an administrator to block traffic (or leave if his)

a false positive in IPS) without having to connect to the ASDM?  If you have a scenario where you don't want to give users access to

the firewall, what is the best way to go about this?

Who should perform the analysis of IPS events have generally sufficient privilege and access to make any changes necessary to your firewall security and IPS sensors. It takes time, knowledge and skills for the analysis of the IPS. Most customer do not have the resources to do the job that you describe.

5. is it possible to set up an alert that if this is a DDOS email alert, if it's a handshake of split then just syslog alert?

No syslog. You can set alerts email on a per-signature basis.

6. I'm afraid that if I put it with a profile he can start blocking valid traffic.  What is the best way to start with IPS to protect

a server?

Start in "Promiscuous" mode and see what hit the signatures. Investigate them, adjust your false positive until you have a tight game, an action of signatures. Then switch to online mode.

7 if its possible to syslog, what kind of detail is the capture of syslog?  Need name attack, etc.?

No syslog.

-Bob

Tags: Cisco Security

Similar Questions

  • Detection of injections SQL with IDS/IPS on cisco ASA?

    Hello

    Is it possible to detect or prevent attacks by injecting SQL using Cisco IDS / IPS on ASA or with regular expressions?

    Is any signature available in IDS/IPS for this? And what is effective, is in terms of the generation of correct alarms?

    Thanks in advance

    Deepak,

    We have several signatures to detect generic SQL injection attacks in the family x-5930 of signatures.

  • The ACE IPS Cisco and Cisco ASA AIP - SSM (IPS)

    Is there a difference between the features offered by the Cisco ACE IPS and Cisco ASA AIP - SSM (IPS) devices?

    Can we do without Cisco ASA AIP - SSM (IPS) of 'only' configuration/implementation Cisco ACE IPS.

    Cisco AVS/ACE emphasis on commissioning and to secure web-based applications. IP addresses do not focus on just the web applications and trying to get the multiple layers of the OSI stack. Consider the IPS as a general practitioner and the ACE/AVS as an eye surgeon, or something :)

    Here is the response from Cisco itself:

    http://www.Cisco.com/en/us/prod/collateral/modules/ps2706/ps6906/prod_qas0900aecd8045867c_ps6492_Products_Q_and_A_Item.html

    Q: how is Cisco AVS Firewall application differs from an intrusion prevention system (IPS)?

    A. IPSs are solid solutions of protection against targeted attacks of known vulnerabilities in major platforms such as Windows, Solaris, Apache or Microsoft Internet Information Services (IIS). Cisco AVS excels to protect against targeted attacks Web sites or enterprise applications. These applications can be built custom internal applications or software vendor. Signatures and security patches are generally not available for these types of applications, and building these security levels in each application, it would be almost impossible.

    Q: how is Cisco AVS Firewall application differs by a network firewall?

    A. The Cisco AVS 3120 and Firewall network such as the Firewall of Cisco PIX® and Cisco ASA 5500 Series Adaptive Security appliances are complementary products. The application Cisco AVS Firewall secures Web applications; excellent network in the network security firewall. and the Cisco AVS provides defense in depth for Web applications.

    Firewall network apply policy networks, IP addresses and ports; they have a wide range of application for many different protocols layer features. The firewall can and will be deployed in many locations, including the edge, edge of the enterprise network, branch, etc. Cisco AVS imposed the policy on data HTTP as URL, headers and parameters. Cisco AVS is deployed in the data center in front of Web applications

    Concerning

    Farrukh

  • AAA to circumvent the password to enable on the Cisco ASA

    Hi all. I'm having a problem where I get authenticated by the AAA server, but after authentication, that I am placed in user mode. AAA admin (I have no access to the AAA server) told me that he had all the users configured with priv level 15, which will lead them directly in the mode privilege on routers.

    My question is how can I configure my Cisco ASA to get around using a password to enable. See below the configuration of my

    AAA-server protocol Ganymede MYGROUP +.
    Max - a failed attempts 4
    AAA-server host 2.2.2.2 MYGROUP (inside)
    timeout 3
    key *.
    Console Telnet AAA authentication LOCAL MYGROUP
    Console to enable AAA authentication LOCAL MYGROUP
    privilege MYGROUP 15 AAA accounting command

    Looks like you want to directly access the exec privileges mode. This feature is not supported by the ASA. This is only possible on IOS devices.

    Rgds, jousset

    Note the useful questions.

  • Program compatibility cannot download antivirus Avira - Avira Pre installation download program block him

    I try in vain to download the free Avira antivirus program - it blocks every time on Avira Pre installation (not compatible)

    Please select your language from the drop-down menu at the bottom of the page to post your question in the language of your choice. The forum in which you've posted is for English only. If you can't find the desired language, support for additional international sites options are by following the link below:

    Hello

    Please get your language in the drop-down list above pour post your question in the language of your choice. The forum you posted is in English only. If you can't find the language of your choice above, options of fees to pay to other international destinations can be found by following the link below:

    Thank you

    http://support.Microsoft.com/common/international.aspx

  • pre installation of software drivers/OSX

    I am replacing a C410a all-in-one

    with a HP 8620 on MAC OSX 10.10.1 (not listed down to the bottom)

    I have not yet received the 8620

    I was thinking of driver software pre-installation and nothing else than installing the software

    any of you recommend it?

    also;

    Recently, I got nothing else that issues with a correct reinstallation of the C410a (I uninstalled and reinstalled according to the instructions from HP

    Now I confused my MAC with this new facility?

    everything worked very well until Yosenomite was released.

    a call to Apple support has helped a bit but not completely

    I refused to call HP support and pay them because I can never understand the technical support

    in this case, it will be different because it will be a new product.

    So I guess my question is, should I pre install anything? I'm sure the installation disc does NOT include the installation of OSX, and I'll have to download from the HP site. I also have Windows Vista, but have no problems with the initial installation on this OS

    Thanks, Bob (eickides)

    Robert Eick

    Hello @eickides,

    Welcome to the Forums of HP Support!

    I would like to help you with your installation questions and problems you're having with your computer Mac OS X 10.10 today.

    The HP Officejet Pro 8620 e-all-in-one printer that you'll be buying and using a computer Mac OS X 10.10 is now completely cared for and functional operating system. There is absolutely no reason why you can't go ahead and preinstall the device Drivers and software for this printer on your Mac to get everything prepared and ready for when you actually get your printer.

    If you want to download your printer drivers, please click here and simply select the "download" button in the upper left corner of the page. You can complete the whole installation. However, at the end installation, you will be prompted to "Add" your printer to your folder of printing & scanning. Of course this is not possible until you actually have the printer, so just close that box. Once you get the printer and all up you can easily add in the Mac. If you have problems with who simply join the HP Support Forums of step by step quick assistance.

    With regard to your HP Photosmart Premium Fax e-all-in-one printer on your Mac OS X 10.10 HP C410a doesn't have a comprehensive set of features and software download. Therefore, you rely solely on Apple updates to load this basic generic in driver package. In no case this generic Apple package will interfere with your HP Officejet 8620. Therefore, if you want assistance with loading C410a C410a on your Mac, please follow the steps below:

    Step 1: Uninstall the drivers and software:

    Please unplug your USB cable from your C410a before continuing.

    To ensure that we have a nice clean slate to work with during the installation of the driver correctly for your C410a please click here and through the supplied instructions to uninstall. When the page opens, select the drop-down menu 'Mac OS X v10.6, OS X v10.7, OS X v10.8 and OS X v10.9' that the steps are identical for Mac OS X 10.10. Please run the two method: reset the printing system, and second method: uninstall the printer software.

    Once the uninstall is complete, proceed to the next step.

    Step 2: Check and repair your Mac disk permissions:

    1. Open Macintosh HD and go to Applications
    2. Go to the Utilities folder
    3. Open disk utility
    4. Select the hard disk volume, you use (usually on the left)
    5. Select verify disk permissions
    6. Once this process is complete, select repair disk permissions

    Step 3: Check the Apple updates:

    1. Please plug in your USB cable now.
    2. Select System Preferences
    3. Select software update
    4. Click update now
    5. Install your available updates
    6. Computer restart

    Step 4: Add your printer:

    1. click on the menu Apple and then click on System Preferences.

    2. Select Print & Scan

    3. check if the name of your printer appears in the list of Printers .

    4. carry out the following operations, according to you whether or not the printer is listed:

    • If your printer is listed, remove and re-add the printer to check the communication with the Mac. Click on the name of your printer, click the sign minus (), then remove the printer. Once the printer is deleted, click the plus sign (), click Add a printer or a Scanner, click the name of your printer
    • If your printer is not listed, click the sign plus (), click Add a printer or a Scanner, click the name of your printer

    5. click on the area of use or with the help of Print and then select the name of your printer on the shortcut menu.

    6. click Add to add the printer to the list.

    7. close Print & Scan

    Now, try to print.

    Please let me know if the information I have provided fixes your driver issues and if the steps I provided helped to reinstall your C410a. I look forward to hear from your part. happy new year!

  • EBS Version 12.2 CUP5 - patches of pre-installation

    Hi people,

    I'm upgrading my current version of BSE 12.1.3 to 12.2.4 referring, "Upgrade Guide reference no.. E48839-02".»

    I did ' apply AD 12.2 update driver (required) "stage which is on page #"3-4 Oracle E-Business Suite Guide upgrade.

    Now I'm going to "apply all the patches (cups) consolidated upgrade (required)" according to guide.

    I followed the DOC ID: 1448102.2.

    According to the MOS DOC, I downloaded "EBS_R12.2_Preinstall_2015_Jun_19.zip". This shows a number of patches that I need to apply with patch 18007406, mode of pre-install.

    I ran the following query on my machine, which shows that most of the products is at the level of the B.3.

    SELECT app_short_name, MAX (patch_level)

    OF apps.ad_patch_driver_minipks

    GROUP BY app_short_name;

    Output:

    ------

    PSP R12. PSP. B.3

    AS R12.AS. B.3

    FTE R12. FTES. B

    AK R12. AK. B.3

    HVC R12. HVC. B.3

    and so on...

    My question is:

    (1) do I apply all patches listed by the DOC in mode of pre-installation or only patches which the product is currently available in my system?

    (2) Let's say in my system ("PAY"R12 is at .) PAY. B.3, code level). When I download the patch against the product (i-e: 19730774), it shows that the patch is (Compatible with: R12.) PAY. C, R12.HR_PF. (C) and my current level of PAY product code is "R12. PAY. B.3. So I have to jump these patches that are not available for my current level of code?

    Thank you!

    Ali

    To download the patches one by one is going to be a tedious task you better use a download script (Wget for 12.2 clients Upgrade) provided by note 1448102.2 which will download the patches all pre-installation.

    For the line of code 12.2 is C

    Please find Note 1325930.1 what are the codelines? Codelevels?

  • Database checks pre-installation of warning/error

    I need help, find a solution to the question below.

    Details of control system:

    Checks of preinstallation of database

    These controls may take a few minutes...

    command: cmd.exe /c C:\stage122\startCD\Disk1\rapidwiz\bin\checkOS.cmd

    C:\stage122\startCD\Disk1\rapidwiz > ECHO OFF

    File not found

    File not found

    FINDSTR: Cannot open C:\Users\ADMINI~1\AppData\Local\Temp\2\\

    (all was unexpected at this time.

    RW-50011: error:-test version of the fix/operating system returned an error: 255Database pre-installation checks completed.

    This is the only error I get on install. Let me know if any other information is needed for the resolution.

    I would like to redo the installation of the database-level node and the password apps would be 'apps' default.

    You can share the directory of the scene between the nodes.

    Thank you

    Hussein

  • GR 11, 2 pre Installation fixed

    Hello

    Just a quick question, I have already installed oracle 11 GR 2 on linux distributions that are not officially supported as ubuntu.

    I have installed OEL 5.5 recenty and I was just wondering if I could install GR 11, 2 in unpacking simply by running YES?

    as apose to fixes as follows for ubuntu:

    http://www.Pythian.com/news/13291/installing-Oracle-11gr2-Enterprise-Edition-on-Ubuntu-10-04-lucid-Lynx/

    or do I need a similar process when installing on oel?

    see you soon

    As long as you meet all the pre-installation requirements described in the Installation Guide, you should be good

    http://download.Oracle.com/docs/CD/E11882_01/install.112/e16763/pre_install.htm#BABFDGHJ

    HTH
    Srini

  • Cisco ASA with the power of fire vs Cisco IPS Appliance

    Hello

    Question: is there the functional differences between an ASA with the feature of firepower enabled and power of fire IPS appliances 'pure' (e.g. 7000 and 8000 series IPS Modules)?

    Thank you very much!

    Kind regards

    David

    Hello team,

    The same features except hardware bypass and another should trhougputs. Of course the flow rate will be high for hardwrae devices and it also has the ability to bypass equipment. Apart from that URL and all other filtering the same characteristics.

    Rate of good will if this post helps you.

    Concerning
    Jetsy

  • Cisco asa 5585 syslog options for ips?

    We have CISCO ASA 5585 with a separate module for the IPS, I want to know what are the options for configuring syslog? Its almost impossible to find; and there are some forums on the internet that says cisco ips store the logs in native format / owner and cannot be exported.

    Please provide details

    Thank you.

    Click on the following link

    https://supportforums.Cisco.com/document/47881/SDEE-and-IPS

  • Cisco ASA IPS with enforcement

    Hi all

    I don't know if this is the best place to connect to this application, because it comes to ASA and convenient best IPS.

    In any case, I was wondering what the best approach is to integrate a Cisco IPS GOAL module in an existing configuration of Cisco ASA, which uses the default application in the world control - i.e.

    ---------------------------

    Policy-map global_policy

    class inspection_default

    inspect the preset_dns_map dns

    inspect the ftp

    etc etc.

    global service-policy global_policy

    ---------------------------

    I was keen to inspect all traffic that was OK coming from our Web-based interface in our environment, while I was trying to do something like:

    ---------------------------

    class-map ips

    corresponds to the list of internet access

    !

    ips policy-map

    class ips

    IPS inline fail-closed

    !

    global service-policy global_policy

    service-policy ips outside interface

    ---------------------------

    This configuration would allow inspection of the demand for traffic going from inside to outside, but to redirect traffic from outside within the IPS?

    Thank you

    As for the configuration. It should inspect traffic in both directions as apply you it globally, and the map-IPS policy, it would redirect internet traffic to the inside network.

  • Node simple database pre-installation checks running for 2 hours.

    Not having my first install Oracle EBS on a concert of 16 16 VM drivers, due to the lack of sufficient space on file system, I added a new 900 GB virtual drive and rose to /d01 with lots of reading permanent writing on a BONE 7 OEL.

    Failed to install previous pre-installation check relatively quickly (10 minutes or more), but this control of pre-installation worked for 2 hours now, with no updates.

    ---------------------------

    .........

    Mid-range host ping was successful

    command: / bin/ping - c 1 host - 1.skytap.example.

    PING host - 1.skytap.example (127.0.0.1) 56 (84) bytes of data.

    64 bytes of the host - 1.skytap.example (127.0.0.1): icmp_seq = 1 ttl = 64 time = 0.062 ms

    -Home - 1.skytap.example - ping statistics--

    1 packets transmitted, received 1, 0% packet loss, time 0ms s

    RTT min/avg/max/leg = 0.062/0.062/0.062/0.000 ms

    Mid-range host domain Ping was successful

    Check complete.

    Checks of preinstallation of database

    These controls may take a few minutes...

    --------------------------------------

    The computer is allocate mem and CPU for the gnome, java and the Xorg process, but I expect to see an update now.

    Is there a log somewhere that will tell me if he actively done something or if it is stuck?

    Is there a protocol suitable for wiping system before you try a new installation of a new rest area?

    Is there a log somewhere that will tell me if he actively done something or if it is stuck?

    Is there a protocol suitable for wiping system before you try a new installation of a new rest area?

    What is a 12.2 installation? If so, you should find the details on doing RapidWiz in $TMP //in the .log file - Rapid troubleshooting install for E-Business Suite version 12.2 (Doc ID 1378579.1)

    Thank you

    Hussein

  • Rapidwiz upgrade to R12.2 - Web Server pre-installation verification failed

    Hello people.

    I'm on the right track to improve my EBS 12.1.3 to R12.2. I did all the pre-reqs/patch before the upgrade according to the DOC: Oracle E-Business Suite Upgrade Guide version 12.0 and 12.1 to 12.2 E48839-02 Réf..

    Finally, I run rapidwiz. However, after entering all the required values, when rapidwiz reached the status of control system, after doing several checks he stuck on 'Web server pre-installation check failed ".


    System check the status showing window continues same message for 2 hours. For more information please see the screenshot below.

    systemcheck.PNG

    Please, let me know where rapidwiz creates log file so that I can investigate the reason to fail. Also, please try to fix this.

    Thank you!

    Ali

    Checksums MD5 for R12.2 Quick Install Media (Doc ID 1505510.1) helped me to solve the mentioned problem.

    Thank you

    Ali Raza Memon

  • Is it possible to change the question from pre-test to noted after you create the slides?

    I created a quiz, but all except a slide is in test mode. Classified is grayed out.  Is there anyway to change it now or should I recreate?

    Thank you!

    There is no way to 'upgrade' a question of pre-test to a normal question of graduate, sorry.

Maybe you are looking for

  • Camileo P10 - can use SDHC 16 GB card?

    Camileo P10 - can use SDHC 16 GB card?

  • How to disable the "offline" Mode by default?

    When to start Firefox it starts in offline mode. So I need to switch to the online hand. Is it possible to set the default online mode?

  • HP 6200 Pro SFF i5 processor upgrade

    I'm looking to upgrade my HP 6200 Pro SFF CPU with an i5-2400 or i5-2500. Are all supported processors below? i5-2400 i5-2400 s i5 - 2400 k i5-2500 i5-2500 s i5 - 2500 k I don't know if the processors that ends in s or k are supported on the 6200.

  • How can I download the new Iphone IOS to my windows XP

    I downloaded the new IOS on my iphone 5 and now I can't sync it with my computer and when I try to download the new IOS on my computer, I get a message that the download is now an application valid win 32.  What can I do?   My computer is running Win

  • Express doen't start. [edit] HE IS ALIVE! HE IS ALIVE!

    Hello! Surprise, surprise, my express does not work OK, step by step of what happened: (1) battery failed and the unit turns off (2) by pressing the power button did not a thing instead of display the picture of empty battery (3) when it is connected