Link to home
Start Free TrialLog in
Avatar of cnjbucks
cnjbucks

asked on

ips-4260 not triggering events for port sweeps from certain vlan's

We have a test environment for our IPS.  the connections are router - IPS - switch.  If I do a port sweep from our production VLAN into our test environment (diff VLAN), no event is generated.  It appears there is only one vlan that this works from.  However, if I run a ping sweep from inside our test environment to any vlan in our production network, those come through.

When I run the ping sweep, I do see the number of packets increasing on those interfaces.  

On the IPS, we have an inline pair configured, and no VLAN groups or pairs.  We are using the default virtual sensor, and no rules have been changed other than adding the inline pair to the vs0.
ASKER CERTIFIED SOLUTION
Avatar of cnjbucks
cnjbucks

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial