<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS - Disruption in service in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043403#M54706</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPS would enter in Bypass state when a signature update is happening. Bypass will get triggered during an upgrade as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd008f.shtml#caveats"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd008f.shtml#caveats&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 01 Sep 2012 02:53:01 GMT</pubDate>
    <dc:creator>sawgupta</dc:creator>
    <dc:date>2012-09-01T02:53:01Z</dc:date>
    <item>
      <title>IPS - Disruption in service</title>
      <link>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043400#M54703</link>
      <description>&lt;P&gt;Hey all thanks for reading my post. &lt;/P&gt;&lt;P&gt;Can someone either tell me or point me to a doc that tells me 100% for sure what upgrades in regards to the ips are disruptive. IE: Signatures, Engine, Software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys for all your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rodney&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043400#M54703</guid>
      <dc:creator>Rodney Mothersbaugh</dc:creator>
      <dc:date>2019-03-10T12:45:51Z</dc:date>
    </item>
    <item>
      <title>IPS - Disruption in service</title>
      <link>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043401#M54704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rodney,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your answer lies within the Cisco Intrusion Prevention System Device Manager Configuration Guide for your particular version of IPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link to version 7.0. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idmguide7.html"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idmguide7.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 15:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043401#M54704</guid>
      <dc:creator>turnera</dc:creator>
      <dc:date>2012-08-30T15:06:55Z</dc:date>
    </item>
    <item>
      <title>IPS - Disruption in service</title>
      <link>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043402#M54705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turnera,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info however i still dotn see anywhere that is states that it will be disruptive or it will not be disrutptive during a sugnature and or engine update. I did however see this which i already knew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Major updates, minor updates, and service packs may force a restart of the IPS processes or even force a reboot of the sensor to complete installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still unanswered. But again thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Sep 2012 01:04:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043402#M54705</guid>
      <dc:creator>Rodney Mothersbaugh</dc:creator>
      <dc:date>2012-09-01T01:04:02Z</dc:date>
    </item>
    <item>
      <title>IPS - Disruption in service</title>
      <link>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043403#M54706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IPS would enter in Bypass state when a signature update is happening. Bypass will get triggered during an upgrade as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd008f.shtml#caveats"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd008f.shtml#caveats&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Sep 2012 02:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043403#M54706</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-09-01T02:53:01Z</dc:date>
    </item>
    <item>
      <title>IPS - Disruption in service</title>
      <link>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043404#M54707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;For Signature-Updates:&lt;/STRONG&gt;&lt;/EM&gt; (from the conf-guide, same link that turnera posted):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_sensor_management.html#wp2016113"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/idm/idm_sensor_management.html#wp2016113&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 style="font-size: 13px; color: #336666; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; background-color: #ffffff;"&gt;Signature Updates and Installation Time&lt;/H3&gt;&lt;P&gt; &lt;A name="wp2221687" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;A name="wpmkr2221686" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;There is a short period of time that traffic is not inspected while you are performing signature updates. However, traffic continues to flow if you have bypass enabled.&lt;/P&gt;&lt;P&gt; &lt;A name="wp2221688" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;When a signature update adds or modifies signatures that contain regular expressions, the regular expression cache tables used by SensorApp have to be recompiled. The amount of recompile time varies by platform, number of signatures modified and/or added, and type of signatures modified and/or added.&lt;/P&gt;&lt;P&gt; &lt;A name="wp2221689" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;If a signature update only adds one or two new signatures on a high-end platform, for example, IPS 4255 or IPS 4260, the recompile can be as fast as a few seconds.&lt;/P&gt;&lt;P&gt; &lt;A name="wp2221690" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;The recompile takes several minutes and even up to a half hour under the following conditions:&lt;/P&gt;&lt;P&gt; &lt;A name="wp2221691" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;When a signature update adds a large number of signatures, for example, when you are skipping several signature levels to install a newer one, for example, installing S258 on top of S240.&lt;/P&gt;&lt;P&gt; &lt;A name="wp2221692" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 0px 0em 7px 0.25in; text-indent: -0.25in; background-color: #ffffff;"&gt;•&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;When a signature update modifies a large number of signatures, for example when a large number of older signatures is disabled and/or retired.&lt;/P&gt;&lt;P&gt; &lt;A name="wp2221693" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;During the recompile, SensorApp stops monitoring packets. The interface driver detects this when the packet buffers begin filling up on the way to SensorApp and the driver stops receiving packets from SensorApp. If the sensor is in inline mode, the driver either turns on bypass if the bypass option is set to Auto, or brings down the interface links if bypass is set to Off.&lt;/P&gt;&lt;P style="margin: 0px 0em -10px -0.25in; text-indent: -0.5em; color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;IMG src="http://www.cisco.com/en/US/i/templates/note.gif" /&gt;&lt;/P&gt;&lt;HR style="margin-left: 0in; margin-right: 0em; margin-top: 5px; text-align: right; border-style: solid; border-color: #808080; background-color: #aaaaaa; color: #000000; font-family: Arial, Helvetica, sans-serif;" /&gt;&lt;P&gt; &lt;A name="wp2221694" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 3px 0em 3px 0in; text-indent: -0.3in; background-color: #ffffff;"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="1" /&gt;Some packets can be dropped before the bypass setting begins operating. Once SensorApp completes the recompile of the regular expression cache files, SensorApp reconnects to the driver and begins monitoring again, and the driver begins passing packets to SensorApp for analysis, and if necessary, also brings the interface links back up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;And this is for all other updates:&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 0px 0em 0px 0.88in; text-indent: -0.46in; background-color: #ffffff;"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="6" /&gt;The IDM and CLI connections are lost during the following updates: service pack, minor, major, and engineering patch. If you are applying one of these updates, the installer restarts the IPS applications. A reboot of the sensor is possible. You do not lose the connection when applying signature updates and you do not need to reboot the system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 01 Sep 2012 08:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-disruption-in-service/m-p/2043404#M54707</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-09-01T08:24:16Z</dc:date>
    </item>
  </channel>
</rss>

