cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1599
Views
0
Helpful
2
Replies

Detect attack man in the middle with IDS/IPS

emilioj.romero
Level 1
Level 1

Hi,

I have aip-ssm 20, IPS Version 7.0(6)E4

The ID  signature 7101, 7102, 7104 and 7105 is used for detecting attack arp poison.

The sensor works as IDS in promiscuous mode. All traffic is fordwared to sensor.

I have made attack man in the middle with cain & abel but sensor doesn't send alarm. I attach image with signatures.

Why don't sensor detect attack? The network is in zone inside.

Can anybody help me, please?

2 Replies 2

mkodali
Cisco Employee
Cisco Employee

Did you check if SSM is getting those packets by running "packet display .." command on the sensing interface. In SSM the ARP packets would not be forwarded by ASA to the SSM.

thx

Madhu

Couldn't the sensor detect this kind of attack?

desn`t the signature work  with aip-ssm?

Thx.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card