cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
456
Views
0
Helpful
2
Replies

ASA-AIPSSM

shahkamrah
Level 1
Level 1

Hi,

We are using AIP SSM in the promiscuous mode,And every thing seems to be fine.The only issue i am facing right now is that i cannot see the events which traffic comes from the outside to inside zone.

Interesting traffic for IPS is "IP any any" and the service policy is implemented globally.

I am testing on the ICMP signature and i am able to see the events when i initiate the ping from inside to outside.But i cannot see anything in the events when traffic is initiated from the outside.

Please update me about this..

2 Replies 2

brandon_leiker
Level 1
Level 1

Is the traffic from the outside being dropped at the outside interface? If the traffic doesn't make it past the ACL on the outside interface you probably won't see anything in the IPS.

Thanks for you reply..

In my case the rules on the outside interface are "IP any any"

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: