Cisco IPS-4255-K9 Installation Guide - Page 347

The AIP SSM and the Data Plane, AIM SSP and the Normalizer Engine

Page 347 highlights

Chapter A Troubleshooting Troubleshooting the AIM IPS and the NME IPS For More Information The AIP SSM has the same software architecture as the 4200 series sensors. You can use the same troubleshooting tools as outlined in Troubleshooting the Appliance, page A-23. The AIP SSM and the Data Plane Symptom The AIP SSM data plane is kept in the Up state while applying signature updates. You can check the AIP SSM data plane status by using the show module command during signature updates. Possible Cause Bypass mode is set to off. The issue is seen when updating signatures, and when you use either CSM or IDM to apply signature updates. This issue is not seen when upgrading IPS system software. AIM SSP and the Normalizer Engine The majority of the features in the Normalizer engine are not used on the AIP SSM, because the ASA itself handles the normalization. Packets on the AIP SSM go through a special path in the Normalizer that only reassembles fragments and puts packets in the right order for the TCP stream. The Normalizer does not do any of the normalization that is done on an inline IPS appliance, because that causes problems in the way the ASA handles the packets. For More Information For detailed information about the Normalizer engine, refer to Normalizer Engine. Troubleshooting the AIM IPS and the NME IPS This section contains information for troubleshooting the IPS network modules, the AIM IPS and the NME IPS. It contains the following section: • Interoperability With Other IPS Network Modules, page A-69 Interoperability With Other IPS Network Modules Caution You cannot upgrade an NM CIDS to an NME IPS. The Cisco access routers only support one IDS/IPS module per router. If you have more than one IDS/IPS module installed, the most capable card is enabled. The most capable hierarchy is: 1. NME IPS 2. AIM IPS 3. NM CIDS This means, for example, that if all modules are installed, the NME IPS disables all other modules. The AIM IPS disables all NM CIDS. If there are multiple modules with the same level of capability, the first one discovered is enabled and all others are disabled. OL-18504-01 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 A-69

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412

A-69
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
OL-18504-01
Chapter A
Troubleshooting
Troubleshooting the AIM IPS and the NME IPS
For More Information
The AIP SSM has the same software architecture as the 4200 series sensors. You can use the same
troubleshooting tools as outlined in
Troubleshooting the Appliance, page A-23
.
The AIP SSM and the Data Plane
Symptom
The AIP SSM data plane is kept in the Up state while applying signature updates. You can
check the AIP SSM data plane status by using the
show module
command during signature updates.
Possible Cause
Bypass mode is set to off. The issue is seen when updating signatures, and when you
use either CSM or IDM to apply signature updates. This issue is not seen when upgrading IPS
system software.
AIM SSP and the Normalizer Engine
The majority of the features in the Normalizer engine are not used on the AIP SSM, because the ASA
itself handles the normalization. Packets on the AIP SSM go through a special path in the Normalizer
that only reassembles fragments and puts packets in the right order for the TCP stream. The Normalizer
does not do any of the normalization that is done on an inline IPS appliance, because that causes
problems in the way the ASA handles the packets.
For More Information
For detailed information about the Normalizer engine, refer to
Normalizer Engine
.
Troubleshooting the AIM IPS and the NME IPS
This section contains information for troubleshooting the IPS network modules, the AIM IPS and the
NME IPS. It contains the following section:
Interoperability With Other IPS Network Modules, page A-69
Interoperability With Other IPS Network Modules
Caution
You cannot upgrade an NM CIDS to an NME IPS.
The Cisco access routers only support one IDS/IPS module per router. If you have more than one
IDS/IPS module installed, the most capable card is enabled. The most capable hierarchy is:
1.
NME IPS
2.
AIM IPS
3.
NM CIDS
This means, for example, that if all modules are installed, the NME IPS disables all other modules. The
AIM IPS disables all NM CIDS. If there are multiple modules with the same level of capability, the first
one discovered is enabled and all others are disabled.