Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Testing a ASA - SSM-10

I have a ASA 5520 that I have configured with an ASA -SSM10 card, I have it setup to scan traffic in my lab, is there any site I can use to test that the IPS is actually working?

1 REPLY
Gold

Re: Testing a ASA - SSM-10

There are a lot of ways you can test that your IPS is working. The easiest is to turn on sig 2004 (ICMP Echo Reply) and run a few pings through your ASA.

If you leave it connected to the open internet (outside your firewall or NAT) you'll see lots of garbage internet attacks showing up as events.

If you want to generate some attacks download a copy of Backtrack 4, it's a live DVD of attack tools.

You can also create a custom sig with a known test string in it. then telnet through your ASA and type the string.

- Bob

406
Views
0
Helpful
1
Replies