Cisco IPS make slow copy between linux server

we have 3 subnet A, B, C . Each subnet have some linux servers. Subnet C is protected by cisco IPS 4270.
1)If we config IPS to bypass traffice, copy speed between servers around 10MB/s -> 25MB/s.
2) IF  IPS protect subnetC.
When we copy file from a serrver of SubnetC to subnet A or B, copy speed increase from min to around 20MB/s.
And when we copy file from a serrver of SubnetA or B to subnet C, copy speed very slow around 700kB/s-> 2MB/s
The server used command "scp .... "
So we think there are signatures we should tuning. we have CSM but we havent seen any relate events about this problem.
Help me check this problem!

Hello,
You can do what Jon mentioned, you might see a signature being triggered when Host C takes place but if by any chance you do not then create captures for both traffic flows (With C and Without C).
Afterwards compare
You might find some weird in that TCP session that involes C (packet loss, then retransmissions, ooo packets, etc).
Make sure you correlate all of the information
Rate all of the helpful posts!!!
Regards,
Jcarvaja
Follow me on http://laguiadelnetworking.com

Similar Messages

  • How to use Port to make a connection between Import Server and Source

    Hi guys,
    I wanna make a Import Server and Manager work with a MDM Repository and a Client System. I want the Import Server could listen the port, whenever the Client System want to sent some files to the Import Server, the Server could automatically import files.
    I know how to import a file by hand, but how to make it automatical? Use Port in Type?
    Regards
    Wang Yu
    Message was edited by: Yu Wang

    Hi,
    You can automate the Import or Syndication process using Ports.
    <b>Requirements:</b>
    1. Import Server need to be Installed.
    2. Client Systems need to be defined for the repository.
    3. Create the Port with type Inbound (for Import process). OutBound (for Syndication process)
    4. Associate a predefined map with the Port.
    <b>Note:</b>
    Each port is associated with only one map.
    While creating the ports, When you select the client system, it only populates the maps defined for that client system.
    Make sure if you want to use the same client system for both import and syndication.
      Specify the Client system type as "Inbound/Outbound"
    <b>Steps involved:</b>
    Using MDM Console, In the repository Admin section
    1. Select Client Systems-> this is where you have to define the Client Systems , which you are going to use for the ports.
    Make sure you have define the Import Maps for the specific repository,specific Client System using Import Manager.
    2. Select Ports->This is where you create Port and other related information related to it.
    Once the Port is created, You see a specific directory structure created in the MDM Server installation directory
    <<MDM Server Install_Dir>> ->Distributions -> <<DBMSHOST_DBMS_TYPE>> -> <<Repository Name>> ->
    <<Port Type>> -> <<Client System ID>> ->
    <<Port Code>>
    Under the above sturcture it will have the following directories
    -> Ready
    -> Archive
    -> Status
    -> Log
    <i><b>Ready Folder :</b></i>
    -> In Import Process the import Server will pick up the file from this directory based on the specifc interval you specify in mdis.ini file(This can be found in Import Server installation directory).
    <b><i>Archive Folder:</i></b>
    -> Once the file is picked by the Import Server from Ready folder and if it is processed then the file will be moved to this di
    rectory with some date stamp suffixed.
    <b><i>Log Folder:</i></b>
    ->Log information for that process
    <b><i>Status Folder:</i></b>
    ->Status of process will be kept in this folder.
    Hope this helps.
    Thanks and Regards
    Subbu

  • Seeing continous "Windows Account Locked" alert in Cisco IPS

    Hi,
    Can any one have any idea on why we are seeing huge number of "Windows Account Locked" alert in Cisco IPS device towards only one Windows server.
    We checked whether Windows server is generating any malicious traffic by scanning the server but nothing is found
    Feb 23 2011 20:05:47
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:05:32
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:04:47
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:04:32
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:03:47
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:03:32
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:02:47
    Windows Account Locked
    Cisco Intrusion Prevention System
    Feb 23 2011 20:02:32
    Windows Account Locked
    Cisco Intrusion Prevention System

    Mustafa,
    Here are the signature details:
    http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5605&signatureSubId=0&softwareVersion=6.0&releaseVersion=S262
    This signature detects a Windows SMB user account  that has been locked on the Windows server due to multiple failed logon  attempts, via the "STATUS_ACCOUNT_LOCKED_OUT" message returned to the  client.
    This signature severity is set by default to 'informational'
    Hence all the signature is doing is leeting you know some users were locked out due to multiple logon attempts.
    The event details will also reveal victim ip which might be the machine on which the logon attempts were tried.
    Let me know if this addresses your concern.
    - Sid

  • Difference in data transfer rates between winXP and Linux server?

    Hello all,
    I am using a winXP laptop to act as my server (all usb external hard drives are connected to it) but the data transfer rates can be really slow. Is Linux faster in that regard? Can a Linux based server provide faster data transfer rates?
    Thanks for any help.
    Bmora96

    Linux cannot make hardware go any faster - so if WinXP and its drivers are making optimal use of those USB drives and the USB data transfer pipe, Linux will not make it faster. (but installing Linux and going Tux are always excellent ideas that need no real reason either ;-) )
    Real question you should be asking is if using a notebook in a server role is wise thing to do?

  • How to make CUCM as a TFTP server , then copy files to Voice Gateway ?

    how to make CUCM as a TFTP server , then copy files to Voice Gateway ? anyone knows?

    Hi,
    Please check the following link
    http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/6_1_1/ccmsys/cucm-accm-611/a02tftp.html#wp1023004
    Understanding How Devices Access the TFTP Server
    You can enable the IP phones and gateways to discover the TFTP server IP address in one or more of the following ways, depending on the device type:
    •Gateways and phones can use DHCP custom option 150.
    Cisco recommends this method. With this method, you configure the TFTP server IP address as the option value.
    •Gateways and phones can use DHCP option 066.
    You may configure either the host name or IP address of the TFTP server as the option value.
    •Gateways and phones can query CiscoCM1.
    Ensure the Domain Name System (DNS) can resolve this name to the IP address of the TFTP server. Cisco does not recommend this option because it does not scale.
    •You can configure phones with the IP address of the TFTP server. If DHCP is enabled on the phone, you can still configure an alternate TFTP server IP address locally on the phone that will override the TFTP address that was obtained through DHCP.
    •Gateways and phones also accept the DHCP Optional Server Name (sname) parameter.
    •The phone or gateway can use the value of Next-Server in the boot processes (siaddr).
    Devices save the TFTP server address in nonvolatile memory. If one of the preceding methods was available at least once, but is not currently available, the device uses the address that is saved in memory.
    You can configure the TFTP service on the first node or a subsequent node, but usually you should configure it on the first node. For small systems, the TFTP server can coexist with a Cisco Unified Communications Manager on the same server.
    HTH
    Manish

  • Difference between Original copy and free copy of application server 10g

    what are the difference between Original copy and free copy of application server 10g

    Hi,
    I think that there aren't free copy of Oracle AS.
    If you are a developer or a system architect, you may download Oracle AS for your test.
    Mauro

  • Back up and Restore to make a copy of DB on another server

    I am trying to make a copy of a database on a dev server. I was going to back up the Prod DB on the Prod Server and Restore it on the Dev Server.  When I open the backup dialog, and select a Destination on disk it shows the disk drives on the Prod Server. 
    These are different than the drives I see on the Dev Server.  It doesn't look like I can browse to a directory outside the server.  Don't I need a destination that is available to both Servers? How do I set this up? Can I use my desktop machine?
    Any advice would be appreciated.
    Thanks,
    Mike

    Create a shared folder on dev server and simply use backup statement and provide disk=\\devserver\backup path.
    BACKUPDATABASE Proddb TODISK='\\devserver\backup\Proddb.bak'http://sql-articles.com/articles/general/backup-sql-database-to-remote-location/

  • Client copy between clients having different OS(Linux and Windows)

    Dear All,
    I would like to do client copy between a client in development system having Linux OS and a client in sandbox system
    having Window OS.
    Is it possible?
    Regards,
    Vinod

    You can get more info at ::*
    http://help.sap.com/saphelp_erp60_sp/helpdata/EN/69/c24c0f4ba111d189750000e8322d00/frameset.htm*
    & also check note 552711 which clearly say at point no 5 .*
    5. Can I create client copies in a heterogeneous system landscape?*
                  Remote copies or client transports can also be carried out between different database and operating systems.*
    Please close thread if you feel your question has been answered.*
    Thanks..
    Mohit
    Do NOT post in bold.... 2nd warning.
    Read the "Rules of Engagement"
    Edited by: Juan Reyes on Aug 27, 2009 12:07 PM

  • Error: Cannot connect to NTP server or NTP server is not running - Cisco IPS

    This is different scenario here:
    I have two Cisco IPS 4260-k9 and both are in production now.
    One of the IPSs is configured with NTP and works fines, but another one is not.
    When tried to configure when the device is ON and live in production and got the following error,
    Error from CLI:
    " Error: Cannot connect to NTP server or NTP server is not running "
    Error from IME:
    " Delivery failed.
    err Unaccepable Value - cannot connect to the NTP server or NTP server is not running"
    I am able to reach the NTP server, also the same NTP is working fine with other devices....
    Am I doing anything wrong?
    Please advise

    Hi,
    Now the error has changed:
    Session.connect: java.net.SocketTimeoutException: Read timed out
    I have increased the pooling interval to 1 Hr from 1 Min. Waiting for the next pooling interval result.
    Guide me if I am heading right.... or anything else needs to be done.
    Regards,
    Krishna Chauhan

  • I'm modifying someone else's website for the first time (noob = yes).  I only have ftp access to the site server.  Before uploading changes, is there a easy/quick/recommended/etc way to make a copy of the files I'm about to replace?

    Great, first post, sorry for the title.  But to repeat it:
    I'm modifying someone else's website for the first time (noob = yes).  I only have ftp access to the site server.  Before uploading changes, is there a easy/quick/recommended/etc way to make a copy of the files I'm about to replace?

    You can use the Dreamweaver FTP (or a different FTP client) to completely copy the original website to your development computer, then, before making changes, you can copy the whole thing to a directory called something like "website original"
    If you want to run both the old and new sites on the remote server, this is often possible. Add a folder/directory to the server and call it something like "new" and upload the new files there until you are ready to replace the old site
    All of this you can do with FTP

  • How to to make Cluster between two server 2012 Datacenter with share storage and Hyper-V role then install Exchange 2013 on each server datacenter then make DAG between Exchange servers

    Dears,
    I have IBM Flex server with built in storage,  
    HOW to to make Cluster between two  server 2012 Datacenter with share storage and Hyper-V role then install Exchange 2013 on each server datacenter then make DAG between Exchange servers?
    If there any prerequisites of the Share storage types ?and any configuration guide to deploy Cluster between two Server 2012 datacenter ?

    Microsoft Failover Clusters require shared storage.  If you wish to create a failover cluster with local storage, you need to use third party software to mirror the disks and present it to the hosts (siog.com, datacore.com, starwind.com).  If you
    use third party software, you will need to follow their instructions for configuring the environment.
    Questions on how to configure Exchange environments are better asked in an Exchange forum.
    .:|:.:|:. tim

  • Why My IMAC OS X 10.6.8 Become Slow On The Network Between Window Server 2008

    Dear Sir,
    I am using IMAC 10.6.8, processor 3.06 GHz Intel Core i3, Memory 4GB 1333 MHz DDR3 and now my lovely IMAC become slow on the network between window server 2008 and my IMAC.
    Kindly advise for the above said issue how can I fix it. I already disable in my IMAC IPV6 and I am connect with airport not ethernet cable and my WIFI is LINKSYS modem and all other windows PC's are connected with the Gigabyte switch.
    Awaiting your soonest reply.

    Dear Sir,
    I am using IMAC 10.6.8, processor 3.06 GHz Intel Core i3, Memory 4GB 1333 MHz DDR3 and now my lovely IMAC become slow on the network between window server 2008 and my IMAC.
    Kindly advise for the above said issue how can I fix it. I already disable in my IMAC IPV6 and I am connect with airport not ethernet cable and my WIFI is LINKSYS modem and all other windows PC's are connected with the Gigabyte switch.
    Awaiting your soonest reply.

  • WRVS4400NV2 IPS now blocking Cisco IPS Auto Update Server

    Yesterday I noted that my ASA5505 AIP-SSC5 card was failing to auto  update as it had been doing without issue for months. I looked in the logs and the IPS was  showing an HTTP Error when attempting to update. I checked and nothing  had changed in the IPS configuration. Then, on a hunch, I checked the IPS log of the WRVS4400N which is the edge router for the small business network.
    The WRVS4400N IPS was blocking connections with the cisco auto update  server because it detected an RPC Anomaly in the traffic. So apparently,  something has changed in the cisco IPS auto update server (https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.pl) response that the cisco small business router misidentifies as a threat. . .
    FYI-I also posted this issue to the small business router community discussion forum.

    Yesterday I noted that my ASA5505 AIP-SSC5 card was failing to auto  update as it had been doing without issue for months. I looked in the logs and the IPS was  showing an HTTP Error when attempting to update. I checked and nothing  had changed in the IPS configuration. Then, on a hunch, I checked the IPS log of the WRVS4400N which is the edge router for the small business network.
    The WRVS4400N IPS was blocking connections with the cisco auto update  server because it detected an RPC Anomaly in the traffic. So apparently,  something has changed in the cisco IPS auto update server (https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.pl) response that the cisco small business router misidentifies as a threat. . .
    FYI-I also posted this issue to the small business router community discussion forum.

  • Configure trunk ( dot1q)between Linxux server and a cisco 6500

    Want to know the proper way to configure a trunk on a cisco cat os switch... I'm ruunning a Linux server with the monitoring utility Nagios and I need it to access all my VLANS.
    Ex:
    Running
    On my Linux Server 2 network Interfaces on 10.30.32.11 and 10.30.33.11
    My switch has vlans 31,32,33,34,44,54,64
    Say the the linux server plugs into 6/20 6/21
    Do I first assign each port to a vlan ?
    And then do
    Set trunk 6/20 on dot1q 31-64
    Set trunk 6/21 on dot1q 31-64

    Does the NIC on the server support trunking? You do not need to assign the ports to every VLAN but just one which will be your Native VLAN(Vlan 1 by default).

  • How to disbale  passwd  for  FTP between linux  servers

    Hai,
    reguraly we need to copy file system of one server to another server ( linux). when i was given scp or rsync commnds it prompts for passwd of target server.
    how to disbale this permenanlt?
    how to configure FTP in linux server?

    Hi,
    If what you need is copying files between systems and all have sshd, you can use scp and it won't ask for a password if keys generated in machine1 from the user that will make the connection are trasfered to machine2.
    You can try following this tutorial Link: [http://enrique.barbeito.org/blog/ssh-sin-contrasena/] It's in spanish but I think it's easy to follow; it's the one i followed to avoid password between some of my systems.
    regards

Maybe you are looking for

  • How can I convert an array to image(8bit)

    I can convert an array(acquire from usb camera)to a picture,but not images(8 bit grayscale),how can I do it.many thanks! Attachments: array to image.vi ‏249 KB

  • Recommended tool for technical illustrations to be embedded in FrameMaker document?

    I'm new to Framemaker and don't know, if this is the right tool for me. I have written a technical document of about 500 pages using MS-Word. Now I want to figure out, if FrameMaker would be a good alternative. I think it could be. But one of my need

  • Process Flow - Pass paramters between activities

    Need to pass argument from one mapping/component to next piece. What is the way. Process Flow Editor does not seem to show OUT paramters. Pasting from a previous post Hi, I have a requirement to pass output parameter from a Mapping as input to anothe

  • ICal pop-up alarms are blank

    When my alarms pop up, the names of the events/times are not displayed. Any ideas as to why this is happening? Thanks.

  • Impossible of technical-support?

    I bought Photoshop cs6 design standard  a few days ago. But I had noticed that  normal function is missing. I had contacted Adobe tech-support of korea , and they said to me that no possible technical A/S. Because the product that I bought was bundle