<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS FW/IPS on a 2651XM best practices in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-fw-ips-on-a-2651xm-best-practices/m-p/607487#M100431</link>
    <description>&lt;P&gt;I have a 2651XM with 128MB and I'm trying to figure out what the best practices are as far as IPS is concerned.  I downloaded the latest SDF and I'm trying to load all the threats (excluding the disabled ones) via SDM but for some reason the number that's actually gets applied is always lower than the original number listed when I first select them.  I can see that the router runs out of memory while loading the definitions but I'd guess that that's normal.  This happens even if I just try to load the ones with High severity.  Am I doing something wrong?  What's a good number of definitions given the the specs of my router.  Also, can I automatically block all packets matched against IPS.  Are the built-in definitions a waste of time or should I be using those?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, how would I go about creating my own SDF - I can see that hey come in XML format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance! &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:04:49 GMT</pubDate>
    <dc:creator>ph0enix</dc:creator>
    <dc:date>2019-03-10T10:04:49Z</dc:date>
    <item>
      <title>IOS FW/IPS on a 2651XM best practices</title>
      <link>https://community.cisco.com/t5/network-security/ios-fw-ips-on-a-2651xm-best-practices/m-p/607487#M100431</link>
      <description>&lt;P&gt;I have a 2651XM with 128MB and I'm trying to figure out what the best practices are as far as IPS is concerned.  I downloaded the latest SDF and I'm trying to load all the threats (excluding the disabled ones) via SDM but for some reason the number that's actually gets applied is always lower than the original number listed when I first select them.  I can see that the router runs out of memory while loading the definitions but I'd guess that that's normal.  This happens even if I just try to load the ones with High severity.  Am I doing something wrong?  What's a good number of definitions given the the specs of my router.  Also, can I automatically block all packets matched against IPS.  Are the built-in definitions a waste of time or should I be using those?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, how would I go about creating my own SDF - I can see that hey come in XML format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance! &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-fw-ips-on-a-2651xm-best-practices/m-p/607487#M100431</guid>
      <dc:creator>ph0enix</dc:creator>
      <dc:date>2019-03-10T10:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: IOS FW/IPS on a 2651XM best practices</title>
      <link>https://community.cisco.com/t5/network-security/ios-fw-ips-on-a-2651xm-best-practices/m-p/607488#M100445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use this link for a bereinformaiom.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.snort.org/pub-bin/sigs.cgi?sid=469" target="_blank"&gt;http://www.snort.org/pub-bin/sigs.cgi?sid=469&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jul 2006 19:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-fw-ips-on-a-2651xm-best-practices/m-p/607488#M100445</guid>
      <dc:creator>carenas123</dc:creator>
      <dc:date>2006-07-06T19:17:42Z</dc:date>
    </item>
  </channel>
</rss>

