<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Regarding String XL engines - what devices support them in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042198#M54615</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats good news, thank you. &lt;/P&gt;&lt;P&gt;Is it recommended to retire and disable these signatures for devices that do not support the engines? Also, what is the recommended settings for signatures in relation to promiscuous/in-line - should signatures that do not work be retired?&amp;nbsp; Is there a definitive listing that tells which signatures work (or don't) in promiscuous mode? Also, some way to filter the signatures that do not work in promiscuos mode?&lt;/P&gt;&lt;P&gt;I have also seen signatures that in the definition from CSM, it states that they do not work in promiscuous mode -in other definitions (from web and link from IME), it is not mentioned. Where can I get a definative list and more information regarding this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Allen&lt;/P&gt;&lt;P&gt; sorry about the spelling &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 Sep 2012 13:56:58 GMT</pubDate>
    <dc:creator>afurst</dc:creator>
    <dc:date>2012-09-26T13:56:58Z</dc:date>
    <item>
      <title>Regarding String XL engines - what devices support them</title>
      <link>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042196#M54613</link>
      <description>&lt;P&gt;Greetings &amp;amp; Salutations &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" height="1" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" width="1"&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;In looking at some &lt;S&gt;issues&lt;/S&gt; opportunities we are having, I have some questions regarding the 'String XL Engines'. If I understand correctly, only the specific devices listed at the link would be able to support the signatures that use these engines.&lt;/P&gt;&lt;P&gt;As each signature takes resources, should the signatures that use the XL engines be disabled/retired on a system that doesn’t support them? On the ones that do, the corresponding signature that it supercedes should be disabled/retired, as well.&lt;/P&gt;&lt;P&gt;Why signatures that are dependent on the XL engines would be enabled by default, but not in a consistent fashion, when the parent sig is disabled. On a device that doesn’t support the XL engines, this would create an issue, in coverage, as well as resources. Better yet, why isn’t there an easy, obvious setup for the enabling/disabling/retiring of this group of signatures? &lt;/P&gt;&lt;P&gt;The above would also pertain to the in-line vs promiscuous and asymmetric mode settings/signatures. An automatic (at least group/type) setting of this would help greatly - if the sensor is installed as a promiscuous device the asymmetric mode would be set, as well as the proper signatures would be disabled and retired (e.g. AD 13001-13005). This ability could be buried so that it would not be triggered inadvertently, or by mistake. Perhaps a build/image/package that has a setup for inline and another for promiscuous , this would save a lot of time &amp;amp; effort on everyone’s part. I realze that this may be similar to the signature policies that are not supported by my hardware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some devices will give the following error, while others do not. They are running the same policies, and neither supports the XL engines (according to the docs)&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 8pt; "&gt;&lt;EM&gt;‘Warning:Editing signature xxxx:x for engine &amp;lt;string-xl-tcp&amp;gt; has NO effect - regex hardware is not present or is disabled’.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the docs, none of the devices that I run support the XL engines. I am running SSM10’s, SSM40’s &amp;amp; 4240’s, 4270-20’s at software revision 7.0(8)E4, 7.1(4)E4, 7.1(6)E4 signature S669.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the online 7.1 (and 7.0) configuration guide: &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;The IPS 4345, IPS 4360, IPS 4510, IPS 4520, ASA 5525-X IPS SSP, ASA 5545-X IPS SSP, ASA 5555-X IPS SSP, and ASA 5585-X IPS SSP support the String XL engines and the Regex accelerator card&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Allen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I lost my original post that explains things much better, hopefully this will make enough sense. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042196#M54613</guid>
      <dc:creator>afurst</dc:creator>
      <dc:date>2019-03-10T12:47:06Z</dc:date>
    </item>
    <item>
      <title>Regarding String XL engines - what devices support them</title>
      <link>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042197#M54614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The devices which do not support the String XL Engine, even if string-xl signatures are enbaled/unretired; they won't consume any resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 05:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042197#M54614</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-09-26T05:30:07Z</dc:date>
    </item>
    <item>
      <title>Regarding String XL engines - what devices support them</title>
      <link>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042198#M54615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats good news, thank you. &lt;/P&gt;&lt;P&gt;Is it recommended to retire and disable these signatures for devices that do not support the engines? Also, what is the recommended settings for signatures in relation to promiscuous/in-line - should signatures that do not work be retired?&amp;nbsp; Is there a definitive listing that tells which signatures work (or don't) in promiscuous mode? Also, some way to filter the signatures that do not work in promiscuos mode?&lt;/P&gt;&lt;P&gt;I have also seen signatures that in the definition from CSM, it states that they do not work in promiscuous mode -in other definitions (from web and link from IME), it is not mentioned. Where can I get a definative list and more information regarding this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Allen&lt;/P&gt;&lt;P&gt; sorry about the spelling &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 13:56:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/regarding-string-xl-engines-what-devices-support-them/m-p/2042198#M54615</guid>
      <dc:creator>afurst</dc:creator>
      <dc:date>2012-09-26T13:56:58Z</dc:date>
    </item>
  </channel>
</rss>

