E-83
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
OL-24002-01
Appendix E Troubleshooting
Gathering Information
sends the TCP reset packet to either the attacker or victim depending on the configuration of the
signature. Signatures configured to swap the attacker and victim when reporting the alert can cause the
ASA to send the TCP reset packet to the attacker.
For More Information
For detailed information about event actions, refer to
Event Actions
.
IPS Reloading Messages
Symptom
ASA syslog messages similar to the following are observed and the root cause of the message
is not clear:
%ASA-1-505013: ASA-SSM-10 Module in slot 1, application reloading "IPS", version
"7.1(6)E4" Config Change
%ASA-1-505013: ASA5585-SSP-IPS10 Module in slot 1, application reloading "IPS", version
"7.1(1)E4" Config Change
These messages occur once an hour for sensors not actively being configured or more often for sensors
being configured.
Conditions
ASA adaptive appliances running an affected software version with an ASA IPS module
(ASA 5500 AIP SSMASA 5500-X IPS SSPASA 5585-X IPS SSP) installed that is running IPS 7.1 or
later. The common cause for these messages is global correlation and/or signature updates occurring on
the ASA IPS module that results in these messages being generated for some, but not necessarily all of
the updates, which are attempted every five minutes.
Workaround
None. The cause of these messages can be confirmed on the sensor module by reviewing the
show events status
past
command output and identifying a status event that corresponds to the ASA
syslog message that matches the date and time. The sensor’s status event should provide further details
about what operation occurred that resulted in the ASA syslog message.
Gathering Information
You can use the following CLI commands and scripts to gather information and diagnose the state of the
sensor when problems occur. You can use the
show tech-support
command to gather all the information
of the sensor, or you can use the other individual commands listed in this section for specific
information.
This section contains the following topics:
•
Health and Network Security Information, page E-84
•
Tech Support Information, page E-84
•
Version Information, page E-89
•
Statistics Information, page E-91
•
Interfaces Information, page E-104
•
Events Information, page E-105
•
cidDump Script, page E-109
•
Uploading and Accessing Files on the Cisco FTP Site, page E-109