<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Incremental IPS signatures maintenance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264633#M53562</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is not staying on the latest version - which is what I do. The problem, actually, is I am avoiding a "reinstall" of IPS feature. As said, there are 50+ "&lt;SPAN style="font-size: 10pt;"&gt;iosips-sig-default-SXXX.xmz" incremental files on my flash:ips/ folder. Since last year updating via SDM was the only available option; by S648 Cisco stopped publishing new .pkgs and at that time I had plenty of dead routers, literally out of any recovery, because of the combo IOS 15.0M and auto-updates (please read &lt;A href="http://tools.cisco.com/security/center/viewBulletin.x?bId=464&amp;amp;year=2012"&gt;http://tools.cisco.com/security/center/viewBulletin.x?bId=464&amp;amp;year=2012&lt;/A&gt;). I have recently open a new TAC and, after some internal testing, they resumed publishing .pkg files again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auto signature update is not an option since then, so the only way to be back on track was using SDM. That and a manual change control process helped, but again, it is a freakin' time &lt;SPAN style="font-size: 10pt;"&gt;consuming process&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;, not only to deploy signatures but also to recover routers back after power loss. Hence my latest TAC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, I was wondering if, by applying the latest .pkg via CLI ("copy IOS-SXXX-CLI.pkg idconf") I could get rid of all those "iosips-sig-default-SXXX.xmz" files and reduce my effective reload times back to less than an hour. If there is no other way to reuse currently deployed sig files, I guess I should plan to clear and reapply IPS feature from the current .pkg file. That will be fun... *sigh*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Jul 2013 01:01:25 GMT</pubDate>
    <dc:creator>HQuest</dc:creator>
    <dc:date>2013-07-23T01:01:25Z</dc:date>
    <item>
      <title>Incremental IPS signatures maintenance</title>
      <link>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264631#M53560</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the recommended way to maintain all incremental IPS signature files created from periodic signature updates? I noticed my small 880 series routers (yeah, I use the cheap IOS IPS) restarts IPS engine for each and every incremental file available; since each restart takes close to a minute, it takes forever to return a router to its working state after any extended power outage, when you have, let's say, a couple months worth of signature updates (from S638 to S725).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I clear the IPS and restart it from scratch using the latest pkg/zip combo as found on SDM, just use the pkg file via CLI, or is there any command I could use to maybe merge all those incremental files?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions are welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:00:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264631#M53560</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2019-03-10T13:00:38Z</dc:date>
    </item>
    <item>
      <title>Incremental IPS signatures maintenance</title>
      <link>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264632#M53561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alexandre,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I would actually recommend always stay on the latest version for that you could get the package manually as u said or go ahead and configure auto-signature update&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Networking Posts check my blog at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.laguiadelnetworking.com/category/english/"&gt;http://www.laguiadelnetworking.com/category/english/&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 00:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264632#M53561</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-07-23T00:26:02Z</dc:date>
    </item>
    <item>
      <title>Incremental IPS signatures maintenance</title>
      <link>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264633#M53562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is not staying on the latest version - which is what I do. The problem, actually, is I am avoiding a "reinstall" of IPS feature. As said, there are 50+ "&lt;SPAN style="font-size: 10pt;"&gt;iosips-sig-default-SXXX.xmz" incremental files on my flash:ips/ folder. Since last year updating via SDM was the only available option; by S648 Cisco stopped publishing new .pkgs and at that time I had plenty of dead routers, literally out of any recovery, because of the combo IOS 15.0M and auto-updates (please read &lt;A href="http://tools.cisco.com/security/center/viewBulletin.x?bId=464&amp;amp;year=2012"&gt;http://tools.cisco.com/security/center/viewBulletin.x?bId=464&amp;amp;year=2012&lt;/A&gt;). I have recently open a new TAC and, after some internal testing, they resumed publishing .pkg files again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auto signature update is not an option since then, so the only way to be back on track was using SDM. That and a manual change control process helped, but again, it is a freakin' time &lt;SPAN style="font-size: 10pt;"&gt;consuming process&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;, not only to deploy signatures but also to recover routers back after power loss. Hence my latest TAC.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that, I was wondering if, by applying the latest .pkg via CLI ("copy IOS-SXXX-CLI.pkg idconf") I could get rid of all those "iosips-sig-default-SXXX.xmz" files and reduce my effective reload times back to less than an hour. If there is no other way to reuse currently deployed sig files, I guess I should plan to clear and reapply IPS feature from the current .pkg file. That will be fun... *sigh*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 01:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/incremental-ips-signatures-maintenance/m-p/2264633#M53562</guid>
      <dc:creator>HQuest</dc:creator>
      <dc:date>2013-07-23T01:01:25Z</dc:date>
    </item>
  </channel>
</rss>

