Testing a ASA - SSM-10

Unanswered Question
Feb 24th, 2010
User Badges:

I have a ASA 5520 that I have configured with an ASA -SSM10 card, I have it setup to scan traffic in my lab, is there any site I can use to test that the IPS is actually working?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
rhermes Wed, 02/24/2010 - 15:48
User Badges:
  • Gold, 750 points or more

There are a lot of ways you can test that your IPS is working. The easiest is to turn on sig 2004 (ICMP Echo Reply) and run a few pings through your ASA.

If you leave it connected to the open internet (outside your firewall or NAT) you'll see lots of garbage internet attacks showing up as events.

If you want to generate some attacks download a copy of Backtrack 4, it's a live DVD of attack tools.

You can also create a custom sig with a known test string in it. then telnet through your ASA and type the string.


- Bob

Actions

This Discussion