rhermes

Member Since: Aug 19, 2003

English
rhermes's Activity on Cisco Support Community
Currently displaying 50 results

rhermes has commented on Configuring 4255 sensor in promiscuous mode

1 year 4 months ago
You want to do a VACL capture on the 6500: http://www.cisco.com/c/en/us/...

rhermes has commented on SSM-10 upgrade in Failover ASA (Active/Standby)

1 year 4 months ago
It all depends on your Fail Open setting and your security posture.If your...

rhermes has commented on Finding the mac address on 4255 IPS appliance

1 year 4 months ago
The 5 GigE sensing interfaces do have have MAC addresses.In Promiscious Mode,...

rhermes has commented on Is it possible for SSM-20 to stream to syslog?

1 year 6 months ago
No, you can't send events to the ASA.SNMP Traps was the workaround. There is no...

rhermes has commented on Is it possible for SSM-20 to stream to syslog?

1 year 6 months ago
None of the Cisco IPS sensors can generate syslog messages for signature events...

rhermes has commented on ASA IPS Test

1 year 6 months ago
There is no need to get complex for testing signature detection and if your...

rhermes has commented on Signature to prohibit delete of files/folders on ftp server

1 year 6 months ago
It would be possible to create a TCP session signature that would trigger on...

rhermes has commented on ASA IPS Test

1 year 6 months ago
Biandov -You are correct, I did neglect to take Promiscuous mode ACL shunning...

rhermes has commented on ASA IPS Test

1 year 6 months ago
If your ASA AIP-SSM module is in promiscious mode, then you can't block...

rhermes has commented on SNMP Traps on ASA5585-SSP-IPS10

1 year 6 months ago
You need to do this on a per-signature basis. There is no global "send all my...

rhermes has commented on IPS 7.1 Event Analysis

1 year 7 months ago
I don't have any experience with Splunk and Cisco IPS, but there is a Wiki for...

rhermes has commented on IPS 7.1 Event Analysis

1 year 7 months ago
Daniel -Your two most common options for getting event data off your sensors...

rhermes has commented on Tuning IPS Signatures in an Industrial Network

1 year 7 months ago
Rene -Enabling all the signatures on your IPS may not be in your best interests...

rhermes has commented on Preventing or stopping attack with no signature or disabled signature

1 year 7 months ago
Jhun -There are several reasons why a signature may be disabled by default, but...

rhermes has commented on Switch config for Inline Interface Pair

1 year 8 months ago
Your IPS appliance will bridge the traffic between the two VLANS. Assign your...

rhermes has commented on ASA IPS Transparent Design Solution Needed

1 year 8 months ago
You ask a lot of questions without providing any detailed information.ASSUMING...

rhermes has commented on Switch config for Inline Interface Pair

1 year 8 months ago
What are you using for an IPS, an appliance? an IOS IPS in the Internet router...

rhermes has commented on IPS Event Victim IP is 0.0.0.0

1 year 8 months ago
Juhn -Yes, anytime you see the 0.0.0.0 address used in the victim IP address...

rhermes has commented on ASA IPS Transparent Design Solution Needed

1 year 8 months ago
Avit -If you read my responses carefully, you'll find all the answers to your...

rhermes has commented on ASA IPS Transparent Design Solution Needed

1 year 8 months ago
You orginaly stated that you wanted to place an ASA5525-X between the external...

rhermes has commented on IPS Event Victim IP is 0.0.0.0

1 year 8 months ago
You can edit the signature to change the summarization and force it to fire for...

rhermes has commented on ASA IPS Transparent Design Solution Needed

1 year 8 months ago
The first design issue is that you are being asked to place an IPS sensor...

rhermes has commented on IPS 4240 Booting Problem

1 year 8 months ago
I am not familiar with the format of the 4240 flash, so I can;t comment on any...

rhermes has commented on IPS ASA-SSM license update

1 year 8 months ago
It appears your AIP-SSM20 is configured to use an http proxy to connect to the...

rhermes has commented on IPS and DDOS protection

1 year 8 months ago
Cisco IPS sensors can provide limited DDoS protection under a small set of...

rhermes has commented on IPS 4240 Booting Problem

1 year 8 months ago
You are doing everything correctly to reimage your sensor.You should be able to...

rhermes has commented on Need to update IPS Sensor and Signature

1 year 8 months ago
In IPS 7.0(8)E4 the default value of the Cisco server IP address has been...

rhermes has commented on IPS SSM 20 software upgrade

1 year 8 months ago
You can use either method to upgrade your sensor.In IME, go to the...

rhermes has commented on IPS SSM 20 software upgrade

1 year 8 months ago
Have you ever searched for and downloaded a router software update?If you have,...

rhermes has commented on Error connecting to sensor. Error loading sensor

1 year 8 months ago
Rebel -Your SSM setup looks correct, but your problem is the lack of network...

rhermes has commented on blocking torrentz in ips

1 year 8 months ago
Last time I tested Cisco's ability to block Bit Torrent traffic (about 2 years...

rhermes has commented on IDSM-2 email question

1 year 8 months ago
There isn't an option for Emailing alerts from the IPS Sensors (including the...

rhermes has commented on Anomaly Detection Knowledge Base

1 year 8 months ago
ArashYour IPS Sensors need to build this database on their own, based on the...

rhermes has commented on Error connecting to sensor. Error loading sensor

1 year 8 months ago
Your "sh mod 1" looks good. It's also a good sign that you can get into your...

rhermes has commented on Cisco IPS make slow copy between linux server

1 year 8 months ago
Don;t forget the Normalizer engine signatures that do not report when they fire...

rhermes has commented on Error connecting to sensor. Error loading sensor

1 year 8 months ago
It sounds like your AIP-SSM is sick. It shouldn't reject a "session 1"...

rhermes has commented on Upgrade to IPS version 6?

2 years 1 month ago
Your backup plan would be to reimage the sensor from scratch with the OS...

rhermes has commented on IPS Promiscous VLAN Groups

2 years 1 month ago
You do not need to run two virtual sensors in order to do this. Your signature...

rhermes has commented on Is there a command to know the current throughput fo an IPS

2 years 1 month ago
I had a script that would log in, run a "show stat analysis" twice, 60 seconds...

rhermes has commented on Configuring IDSM in promiscuous mode?

2 years 2 months ago
Not that I know of, but since Promiscious mode won;t effect yoru traffic, I;d...

rhermes has commented on Configuring IDSM in promiscuous mode?

2 years 2 months ago
The IDSM doesn;t need any special commands to inspect traffic in Promiscious...

rhermes has commented on Cisco ASA 5555-s with IPS License question

2 years 2 months ago
Yes, the IPS sensors are licensed annually. If you have more than one sensor (...

rhermes has commented on Configure ASA5515-X with IPS as standalone IPS.

2 years 2 months ago
We've done this with ASA5500 models, so it's a safe bet you could do this with...

rhermes has commented on Monitoring AnalysisEngine via SNMP

2 years 3 months ago
We've been plauged by this problem for years. We set up a custom sig that...

rhermes has commented on IPS 4240 Series

2 years 3 months ago
Are you trying to put this 4240 in line?If you have a switch on each rail of...

rhermes has commented on Unable to login into IDSM-2 through session slot

2 years 3 months ago
Show us the output of a "show module" on the 6500 to see what state your...

rhermes has commented on IPS system with 20 Gb eth ports

2 years 3 months ago
The interface standard speeds are 1, 10 and 40 Gb/s. I;m not aware of any...

rhermes has commented on SSM40 and ASA Config

2 years 3 months ago
It looks correct.You can try enabling the ICMP Echo Request signature and...

rhermes has commented on Promiscuous mode AIM-SSM-10

2 years 10 months ago
Jeff -Those modules support promiscious mode. Here's a sample configureation...

rhermes has commented on AIP-SSM License Renewal

2 years 10 months ago
Sorry I can;t help with your part number question. As far as your sensor...

Bio












rhermes's Stats

Points831
Discussion started 16
Answers marked as Correct 88
Endorsed 0
Content Rated 149