[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 459
  • Last Modified:

ips-4260 not triggering events for port sweeps from certain vlan's

We have a test environment for our IPS.  the connections are router - IPS - switch.  If I do a port sweep from our production VLAN into our test environment (diff VLAN), no event is generated.  It appears there is only one vlan that this works from.  However, if I run a ping sweep from inside our test environment to any vlan in our production network, those come through.

When I run the ping sweep, I do see the number of packets increasing on those interfaces.  

On the IPS, we have an inline pair configured, and no VLAN groups or pairs.  We are using the default virtual sensor, and no rules have been changed other than adding the inline pair to the vs0.
0
cnjbucks
Asked:
cnjbucks
1 Solution
 
cnjbucksAuthor Commented:
I opened a TAC case with Cisco for this.  It turns out that only certain ping sweep applications with trigger an event on the IPS.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now