<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic signature definition files (SDF) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/signature-definition-files-sdf/m-p/1794066#M56462</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What’s this file for and why do i need it - namely &lt;STRONG&gt;IOS-S573-CLI.pkg&lt;/STRONG&gt; if I already have the &lt;STRONG&gt;256MB.sdf &lt;/STRONG&gt;file to load via the SDM onto the router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the two files complement each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also downloaded this file: &lt;STRONG&gt;sigv5-SDM-S555&lt;/STRONG&gt; but I am not sure what it does?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone used Cisco Configuration Protocol (CCP) to upload the signature definitions to the router or is it easier to do it via the SDM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice appreciated.&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:26:39 GMT</pubDate>
    <dc:creator>ohareka70</dc:creator>
    <dc:date>2019-03-10T12:26:39Z</dc:date>
    <item>
      <title>signature definition files (SDF)</title>
      <link>https://community.cisco.com/t5/network-security/signature-definition-files-sdf/m-p/1794066#M56462</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What’s this file for and why do i need it - namely &lt;STRONG&gt;IOS-S573-CLI.pkg&lt;/STRONG&gt; if I already have the &lt;STRONG&gt;256MB.sdf &lt;/STRONG&gt;file to load via the SDM onto the router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the two files complement each other?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also downloaded this file: &lt;STRONG&gt;sigv5-SDM-S555&lt;/STRONG&gt; but I am not sure what it does?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone used Cisco Configuration Protocol (CCP) to upload the signature definitions to the router or is it easier to do it via the SDM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice appreciated.&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-definition-files-sdf/m-p/1794066#M56462</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2019-03-10T12:26:39Z</dc:date>
    </item>
    <item>
      <title>signature definition files (SDF)</title>
      <link>https://community.cisco.com/t5/network-security/signature-definition-files-sdf/m-p/1794067#M56463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Files with "IOS-SXXX-CLI.pkg" are the most up to date signature files for download from cisco. The files that come with SDM that end in ".sdf" are v4.x signature format. So, depending on the code you have you have a router with supports 4.x or 5.x signature. You can type "show subsys name ips" to figure out which version your IOS supports. In the output of the command if you see Version 3.X then that means it runs version 5.x signature. If you router runs 4.x signature then you will 2.x in the output of the command. (Cisco changed the format of the signatures when going to 5.x so 4.x and 5.x signatures are not compatible.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; In addition, the 256MB.sdf file that comes with SDM only has about 500 signatures that it load. If you load the full &lt;/P&gt;&lt;P&gt;"IOS-SXXX-CLI.pkg" it has something like two or three thousand possible signatures. Lastly, the file "&lt;STRONG&gt;sigv5-SDM-S555.zip" file is what you would load from the GUI of SDM, or CCP. The &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;"IOS-SXXX-CLI.pkg" files I have used to load from the command line.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(I'll admit I haven't played with CCP yet so I can't positively confirm if it will take both SDM or IOS files from the GUI. I mainly have been toying with SDM, which is junk.)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Overall for "easiest deployment" of signatures I would use the command line. However, to do a lot of the tuning it is easier in a GUI. For the command line proceedures see the document below.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hopefully, this all helps. Have a good day.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -Kryptkeepr&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/customer/docs/ios/sec_data_plane/configuration/guide/sec_ips5_sig_fs_ue_ps6441_TSD_Products_Configuration_Guide_Chapter.html"&gt;http://www.cisco.com/en/US/customer/docs/ios/sec_data_plane/configuration/guide/sec_ips5_sig_fs_ue_ps6441_TSD_Products_Configuration_Guide_Chapter.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Aug 2011 17:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/signature-definition-files-sdf/m-p/1794067#M56463</guid>
      <dc:creator>Kryptkeeper</dc:creator>
      <dc:date>2011-08-12T17:12:08Z</dc:date>
    </item>
  </channel>
</rss>

