Unanswered Question
Mar 11th, 2009


We are using AIP SSM in the promiscuous mode,And every thing seems to be fine.The only issue i am facing right now is that i cannot see the events which traffic comes from the outside to inside zone.

Interesting traffic for IPS is "IP any any" and the service policy is implemented globally.

I am testing on the ICMP signature and i am able to see the events when i initiate the ping from inside to outside.But i cannot see anything in the events when traffic is initiated from the outside.

Please update me about this..

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
brandon_leiker Thu, 03/12/2009 - 12:26

Is the traffic from the outside being dropped at the outside interface? If the traffic doesn't make it past the ACL on the outside interface you probably won't see anything in the IPS.

shahkamrah Thu, 03/12/2009 - 20:25

Thanks for you reply..

In my case the rules on the outside interface are "IP any any"


This Discussion