IPs inshared services
Hi There,
Can anyoneplease guide me on this :
How to track the Ips from which user are using their user id in Shared services. For audit purposes which debug or audit flag should be on in the system to track the loggins and activities without affecting the performance.
Thanks,
Are you asking if the IPS portion can be enable with out a subscription?
I am not sure if this answers your question but the 5512-x that I manage was purchased with the CX/IPS license for x-years of updates.
If it makes a difference I also used to manage a 5510 with the IPS module with no subscription. It always bothered me because that is like running an antivirus software with no updates.
Similar Messages
-
How to find out the IPS and DS Service Pack and patch levels in windows server.
Hi,
I have installed the Information Platform Services 4.0 and Data services 4.0 in windows QA system, now we need to install the same version of IPS & DS in windows PRD system for this how could we find out the exact version of IPS & DS ( Service pack and patch levels ) and where we can find the same.
Many Thanks,
SudheerHi Sudheer,
On a Windows Operating Systems you can check the “Programs and Features” in control panel.You can see a list of both the Name and Version number of SAP BusinessObjects that is installed.
option 2:
Open CMC go to Settings. In the properties, you will find the Product Version.
Please check below SAP notes for more information.
http://service.sap.com/sap/support/notes/1602088
Regards,
Pavan -
Cisco IPS Software Update Notification Service
Hi Everybody,
Whilst I'm aware that we can RSS monitor IPS Signature updates; is their an email subsciption service advertising software updates for Security Appliances such as the IDSM-2. Other than using a Cisco Works compliant package are there any standard automated notification processes available.
Thanks in anticipation
MichaelHi,
i just read the below in the release notes of 7.1(8)E4:
You must be running the following versions to upgrade the following platforms to IPS 7.1(8)E4:
- For the ASA 5500 AIP SSM series, you must be running IPS 6.0(6)E4 or later.
So I think I am good to go with downloading the PKG.
However, what's the difference between:
IPS SSM_10 Service Pack Upgrade patch
IPS-SSM_10-K9-patch-7.1-8p2-E4.pkg
and
IPS SSM_10 Service Pack Upgrade
IPS-SSM_10-K9-7.1-8-E4.pkg
Thanks. -
Add E-mail Address in Shared Services
<p>Good Day,</p><p> </p><p>I am using NTLM and like to add e-mail address for my users inShared Services. When i click on the user, i see the User Id,Last Name, First Name, Description and E-mail address field. I cannot change the user profile.</p><p> </p><p>I have asked my Network group who maintains the NT Domain, andthey cannot find any place where the e-mail address is stored. How can i ge the e-mail field populated. I like to usethis function in BI+ Workspace, so that users can e-mail link forreports to other users.</p><p> </p><p>Thanks</p>
That is correct.
-
Hi everybody.
Two 5508 WLCs running 7.4.100.60. I had to activate HA
I decided to configure Service ports: following HA conf guide, I used DHCP. That's because static IPs on service ports are often cleared and forgot during switchover. HA went up perfectly; tests were positive: by rebooting the active unit, standby was immediately ready, and so on.
I decided to test maintenance mode: by shutting down the mgt ports of the active unit, the standby one was activated, and the active went into maintenance mode (because it did not reach the standby). This again is correct.
Issue: when the unit is in this status (maintenance), its service port IS NOT reachable! I have to open again its mgt ports: the unit does not change tha maintenance status (and this is fully correct), but becomes reachable through its service port.
This is not enough: the active unit remembers the peer service port address, but the standby one does not.
Moreover, after some time, when I try to contact the latter, I jump on the former (I am always talking of Service ports).
This is really diffcult for me to explain.... Any suggestion?
Thanks
DavideHi
In my 5508 WLC i have exactly the same problem as you gsutherland
I tried apply this command config 802.11b 11nSupport a-mpdu tx priority all disable
and i get message
"802.11b network not disabled"
Why i must turn off b standard ?
Thanks for respons -
IPS(ASA moduel) signature upgrade cause users lost connectivity to outside
Hi All:
need you adivse.
i have two ASA running A/S mode, both ASA have ASA-SSM-AIP-20-K9 inside with fail-open option and identical configuration
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Table Normal";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:"";
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin:0in;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:11.0pt;
font-family:"Calibri","sans-serif";
mso-ascii-font-family:Calibri;
mso-ascii-theme-font:minor-latin;
mso-fareast-font-family:宋体;
mso-fareast-theme-font:minor-fareast;
mso-hansi-font-family:Calibri;
mso-hansi-theme-font:minor-latin;
mso-bidi-font-family:"Times New Roman";
mso-bidi-theme-font:minor-bidi;}
Any time i upgrade IPS signature/OS, users will experience around 1 minute downtime to outside.
Is this a correct behavior?
ThanksJason;
That is not expected behavior for signature updates. On the AIP-SSM's configuration, have you changed the bypass mode to off?
For software upgrades, which require the AIP-SSM to reboot, a failover of the ASA is expected if you have not disabled the IPS inspection service policy prior to performing the upgrade.
Scott -
How to order IPS Svc for ASA5515-K8 and L-ASA5515-IPS-SSP=?
Hello!
I have got ASA5515-K8 and IPS license L-ASA5515-IPS-SSP= ordered separately.
What smartnet should I order to enable IPS singnature updates?
I tried to order SU1 smartnet for ASA5515-K8, but Product ID ASA5515-K8 is not mapped to SU1 service.
Thank you!Hello Andy,
Here is the information you are looking for:
Cisco Services for IPS
Cisco Services for IPS is an integral part of the Cisco ASA 5500-X Series IPS Solution and enables operators to
receive time-critical signature file updates and alerts. Part of the Cisco Technical Support Services portfolio, Cisco
Services for IPS allows your Cisco ASA 5500-X Series IPS Solution to stay current on the latest threats so that
malicious or damaging traffic is accurately identified, classified, and stopped. Cisco Services for IPS features
include:
● Signature file updates and alerts
● Registered access to Cisco.com for online tools and technical assistance
● Access to the Cisco Technical Assistance Center
● Cisco IPS software updates
● Advance replacement of failed hardware
For more information about Cisco Services for IPS, visit
http://www.cisco.com/en/US/products/ps6076/serv_group_home.html. -
Dear All,
i upgraded my nids 4235 to ips 5.0(1)s49 , but when i logged into the nids it says
There is no license key installed on the system.
Please go to http://www.cisco.com/go/license
to obtain a new license or install a license.
are they charge for this license ?? when i went into this http://www.cisco.com/go/license
i found Cisco Services for IPS service license Cisco Services for IPS service license
Cisco Services for IPS trial license
... these things..which license will work ??
can anybody clear me.. thanks in advance
natarajLicensing is not yet enforced. In the near future it will be required to get sig-updates.
See excerpt from the readme:
IPS SUBSCRIPTION SERVICE LICENSE
You must have a valid maintenance contract per sensor to receive and use
software upgrades, including signature updates from Cisco.com. Beginning with
IPS 5.0, an IPS Subscription Service License is required to install signature
updates.
You can request an IPS Subscription Service License for all sensors covered by a maintenance contract at this URL:
http://www.cisco.com/go/license
To manage your maintenance contracts use the Service Contract Center found at this URL:
http://www.cisco.com/cgi-bin/front.x/scccibdispatch?AppName=ContractAgent
With the initial release of 5.0, the first several signature updates will be
released without the license enforcement to allow you time to get your
maintenance contracts in order and your sensors licensed.
Hope this helps.
-Mario -
Renewal license for ASA5512-IPS-K9
Hi sir,
our customer purchased ASA5512-IPS-K9 from one year, all he want to do is to make a renewal the IPS license and signature update, my question, is any additional license should i offer except the CON-SU1 for the previous model numberThe CON-SU1 line item will cover everything necessary for the base unit Smartnet support and IPS subscription services on an 8x5xNBD basis.
Please see this reference for more details. -
I have a cluster of 2xASA 5525s with software IPS modules. I would like to rename the hostname of each of the IPS modules. This is easy enough but I was wondering how this affects the reporting data in IME. I know the IPS name is used as a PK field in IME so you can't edit it. I'm worried if I delete the devices from IME and re-add them with their new hostnames that the historic data will be lost for the sensors. Is there any way around this? Will IME automatically pick up the new hostname from the ISP meaning I won't have to re-add them?
thank you very much
I re-image ips and "show module" and "session IPS"
ciscoasa# show module
Mod Card Type Model Serial No.
0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525 FCH1623704D
ips ASA 5525-X IPS Security Services Processor ASA5525-IPS FCH1623704D
Mod MAC Address Range Hw Version Fw Version Sw Version
0 a493.4caa.50b3 to a493.4caa.50bc 1.0 2.1(9)8 8.6(1)
ips a493.4caa.50b1 to a493.4caa.50b1 N/A N/A 7.1(4)E4
Mod SSM Application Name Status SSM Application Version
ips IPS Up 7.1(4)E4
Mod Status Data Plane Status Compatibility
0 Up Sys Not Applicable
ips Up Up
Mod License Name License Status Time Remaining
ips IPS Module Enabled perpetual
when loggin IPS display
***LICENSE NOTICE***
There is no license key installed on this IPS platform.
The system will continue to operate with the currently installed
signature set. A valid license must be obtained in order to apply
signature updates. Please go to http://www.cisco.com/go/license
to obtain a new license or install a license.
why no license!! -
I have a asa 5525 and the license with IPS ,but i dont know How usede the IPS issue.anyone can tell me?
thank you very much
I re-image ips and "show module" and "session IPS"
ciscoasa# show module
Mod Card Type Model Serial No.
0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525 FCH1623704D
ips ASA 5525-X IPS Security Services Processor ASA5525-IPS FCH1623704D
Mod MAC Address Range Hw Version Fw Version Sw Version
0 a493.4caa.50b3 to a493.4caa.50bc 1.0 2.1(9)8 8.6(1)
ips a493.4caa.50b1 to a493.4caa.50b1 N/A N/A 7.1(4)E4
Mod SSM Application Name Status SSM Application Version
ips IPS Up 7.1(4)E4
Mod Status Data Plane Status Compatibility
0 Up Sys Not Applicable
ips Up Up
Mod License Name License Status Time Remaining
ips IPS Module Enabled perpetual
when loggin IPS display
***LICENSE NOTICE***
There is no license key installed on this IPS platform.
The system will continue to operate with the currently installed
signature set. A valid license must be obtained in order to apply
signature updates. Please go to http://www.cisco.com/go/license
to obtain a new license or install a license.
why no license!! -
Changing IPs of WiSM2 HA controllers...
hello, experts!!!
HA WiSM2 already setup and running smoothly.
Clients needed to change the IPs of service interfaces.
Can they be changed directly from console of each controller while in HA config
or
need to remove them controllers from HA config?
Removing HA config means disabling just the SSO, right?
then i can proceed with the changing of the IPs?
just wanted to be on the clear.
thanks in advance.Service Interface has nothing to do with HA SSO.
The Service Interface IP address can be changed either through console (better) or by IP. -
Error connecting to sensor. error loading sensor.
Hi all,
I have brand new ASA 5525-X firewall and IPS Security Services Processor ( ASA5525-IPS). There is no any configuration in both devices. I try manage the both device using ASDM-IDM. I can able to access the firewall using default management IP address. But while i try to access IPS
"Error connecting to sensor. error loading sesor" massege is coming. I try to ping IPS management ip address from my pc but i unable to ping.
Please any one can help me to resolve this issue.
ciscoasa(config)# sh module
Mod Card Type Model Serial No.
0 ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC ASA5525
ips ASA 5525-X IPS Security Services Processor ASA5525-IPS
Mod MAC Address Range Hw Version Fw Version Sw Version
0 7c69.f68f.b2b3 to 7c69.f68f.b2bc 1.0 2.1(9)8 8.6(1)2
ips 7c69.f68f.b2b1 to 7c69.f68f.b2b1 N/A N/A 7.1(4)E4
Mod SSM Application Name Status SSM Application Version
ips IPS Up 7.1(4)E4
Mod Status Data Plane Status Compatibility
0 Up Sys Not Applicable
ips Up Up
Mod License Name License Status Time Remaining
ips IPS Module Enabled perpetual
ciscoasa(config)# sh module ips details
Getting details from the Service Module, please wait...
Card Type: ASA 5525-X IPS Security Services Processor
Model: ASA5525-IPS
Hardware version: N/A
Serial Number:
Firmware version: N/A
Software version: 7.1(4)E4
MAC Address Range: 7c69.f68f.b2b1 to 7c69.f68f.b2b1
App. name: IPS
App. Status: Up
App. Status Desc: Normal Operation
App. version: 7.1(4)E4
Data Plane Status: Up
Status: Up
License: IPS Module Enabled perpetual
Mgmt IP addr: 192.168.1.2
Mgmt Network mask: 255.255.255.0
Mgmt Gateway: 192.168.1.1
Mgmt web ports: 443
Mgmt TLS enabled: true
Regards,
Manimaran.Hello Mani,
The network setup on this modules is different than previously so my recommendation is follow the next link, determine which will be your network setup and finally configure everything as properly
http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd5d03.shtml
Then U should be good,
For more information about Core and Security Networking follow my website at http://laguiadelnetworking.com
Any question contact me at [email protected]
Cheers,
Julio Carvajal Segura -
Hi Experts,
On the main abcd.com and the Partner websites, SSRS reports are utilized. When the issue is encountered, the SSRS reports
are the only thing that quit working. The website and various pages that are coded in .NET still work. We have tried to restart the SSRS service but the only thing that seems to fix it is a reboot of the server. We are now rebooting
the server twice every Monday. . Here is the error that the user sees and sent to us:
FYI…. Not able to access your web site. Below is the message being received:
Server Error in '/Partner' Application.
Runtime Error
Description: An
application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server
machine.
Details: To enable the details of this specific error message
to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode"
attribute set to "Off".
I was able to see the error in Event viewer and the error was:
Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database with event id 107, when I googled,, it says to enable TCP/IPS, change service accounts
to Network account and so on, and when checked TCP'S they are enabled and service account is not set to Network account.
Server version is :
Microsoft SQL Server 2008 (SP3) - 10.0.5520.0 (X64)
Jul 11 2014 16:11:50
Copyright (c) 1988-2008 Microsoft Corporation
Standard Edition (64-bit) on Windows NT 6.1 <X64> (Build 7601: Service Pack 1)
Can you please help me out how to proceed with this.
Thanks.Hi venkatesh1985,
Per my understanding that some if the user have got the error message and can't open the web site sometimes, when reboot the reporting services, it works again, right?
I have checked the error message. The SQL Server Report Server service cannot connect to the report server database. This error occurs during a service restart if a connection to the report server database cannot be established.
Conditions under which this error occurs include the following, please check one by one in this articlehttp://msdn.microsoft.com/en-us/library/aa337324.aspx.
You have mentioned that you have check the TCP/IP and the service account, please check if you have also check the information below:
Go to Services. msc and Make sure all the services for SQL Server Database engine and Reporting Services were in the running state.
Then Open the Report Services Configuration Wizard, Connect to the specified SQL Server Database Server and check the connection to the Report Server Database to see if they are connecting to the right DB.
config tool if on the Database tab it says "Service Account" then it is using whatever account the windows service is running as. It is possible someone changed this account via another tool and this account does not have rights to read
the DB.
If your problem still exists, please check if you have config the web.config file correctly:
< !-- Web.Config Configuration File -->
< configuration>
<system.web>
<customErrors mode="Off"/>
</system.web>
< /configuration>
Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.
< !-- Web.Config Configuration File -->
< configuration>
<system.web>
<customErrors mode="RemoteOnly" defaultRedirect="mycustompage.htm"/>
</system.web>
< /configuration>
Similar thread for your reference:
Report Server Windows Service (MSSQLSERVER)
Server Error in '/' Application
If you still have any problem, please feel free to ask.
Regards
Vicky Liu -
VRF issue with Firewall in transparent Mode.
Hi Guys,
I have 7609 Router and 6513 L3 Switch connected Through ASA 5545.
I am running Multiple VRF between router and Switch and BGP routing Protocol. When they are connected directly to each other everything is normal, however, when I have connected them via ASA 5545 then everything fails. I am using ASA in transparent Mode.
My question is: Do ASA require different setting in case of VRF? If yes, then please give me sample config.I have taken following output from Firewall will this be any help?
sh interface ouTSIDE
Interface GigabitEthernet0/1 "OUTSIDE", is up, line protocol is up
Hardware is i82574L rev00, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)
Input flow control is unsupported, output flow control is off
MAC address 7c69.f68f.df78, MTU 1500
IP address 175.4.8.35, subnet mask 255.255.255.248
8435 packets input, 680680 bytes, 0 no buffer
Received 8135 broadcasts, 0 runts, 0 giants
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
0 pause input, 0 resume input
8138 L2 decode drops
0 packets output, 0 bytes, 0 underruns
0 pause output, 0 resume output
0 output errors, 0 collisions, 1 interface resets
0 late collisions, 0 deferred
0 input reset drops, 0 output reset drops
input queue (blocks free curr/low): hardware (476/461)
output queue (blocks free curr/low): hardware (511/511)
Traffic Statistics for "OUTSIDE":
297 packets input, 118503 bytes
0 packets output, 0 bytes
297 packets dropped
1 minute input rate 0 pkts/sec, 13 bytes/sec
1 minute output rate 0 pkts/sec, 0 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 0 pkts/sec, 6 bytes/sec
5 minute output rate 0 pkts/sec, 0 bytes/sec
5 minute drop rate, 0 pkts/sec
ciscoasa# show asp drop
Frame drop:
FP L2 rule drop (l2_acl) 297
ASA Version 9.0(1)
firewall transparent
ciscoasa# show module all
Mod Card Type Model Serial No.
0 ASA 5545-X with SW, 8 GE Data, 1 GE Mgmt ASA5545
ips ASA 5545-X IPS Security Services Processor ASA5545-IPS
Mod MAC Address Range Hw Version Fw Version Sw Version
0 7c69.f68f.df77 to 7c69.f68f.df80 1.0 2.1(9)8 9.0(1)
ips 7c69.f68f.df75 to 7c69.f68f.df75 N/A N/A 7.1(4)E4
Mod SSM Application Name Status SSM Application Version
ips IPS Up 7.1(4)E4
Mod Status Data Plane Status Compatibility
0 Up Sys Not Applicable
ips Up Up
Mod License Name License Status Time Remaining
ips IPS Module Enabled perpetual
ciscoasa#
I have create Ehtertype ACL and permit any traffic.
cdp traffic has passed through but I am still not able to ping :(
Maybe you are looking for
-
External display continuously asleep
I have a 19" extrnal LCD display thats been hooked up to my macbook for over a year with no problems. Suddenly it started to go into an unwakeable sleep mode a couple of times. Both screens went black but computer continued to operate, could only shu
-
Shifting library to external HD
Sorry if this is repeating previously asked questions, but I couldn't find an exact answer... I'm in the process of shifting my library to an new external HD. I want to be sure to keep all the playcount and playlist information. I've copied the whole
-
Is it possible to log an array to a database using only one statement?
I'm using Teststand 2.0.1. Now I can use "database options.." to log single number or string to Oracle database with no problem. But I have the difficulty to log an array to my database by using only one statement. Does Teststand has the ability to l
-
Hi people! I got a problem; during the upload of a sales order from CRM to R/3, I receive the message <b>W V1 555 ('The sales document is not yet complete: Edit data')</b> even though I complete all the obligatory fields. The problem is that I am no
-
Details about ModuleData and ModuleContext
Hi All, I need more deatils about the Module Programming parameters <b>"ModuleData", "ModuleContext" and "XMLPayload"</b> like the members of these classes and their functionalities etc. Looking for your replies. Thanks in advance. Rgds, Joe.