cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
444
Views
0
Helpful
3
Replies

tcp resets in passive mode

jahilnt10
Level 1
Level 1

I know the resets are done by the sensor, not the PIX or router.

Is it possible if my IDS 4235 is working in passvie mode not inline to reset tcp sessions..? If yes than please explain how it does..

3 Replies 3

mhellman
Level 7
Level 7

It is possible. Normally the sensor will send resets out the same sensing interface the traffic was detected on. If it's a hub you're using, it should just work. If it's a switch, it depends on the capabilities of the switch. Refer to the documentation for your switch as to whether it can be configured to allow ingress traffic. Here's an example for the Cisco 2950.

http://www.cisco.com/en/US/products/hw/switches/ps628/products_configuration_guide_chapter09186a00801a6ba9.html#1218090

i think it is not possible to sending tcp RST via sensor that connected to a SPAN port in Catalyst 29xx , 3550 , 3560 , 3750 becuase regarding the SPAN put the port just in ingress mode (no traffic can leave the interface).in higher-level catalyst switched like 65xx , you can use packet capturing done by CLASS-MAP / POLICY-MAP so it can let you have both RX/TX traffic.

The only switch I've tested the TCP RST functionality on is a 2950. It worked fine.

Review Cisco Networking products for a $25 gift card