<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco IPS and  Cisco Mars rollout in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667099#M64993</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about CS Mars.&amp;nbsp; Have you heard of anyone using this product.&amp;nbsp; I thought the idea was to enable IPS on each router and push the syslog traffic back to the CS Mars device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jun 2011 13:19:52 GMT</pubDate>
    <dc:creator>ohareka70</dc:creator>
    <dc:date>2011-06-23T13:19:52Z</dc:date>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667097#M64991</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am preparing to roll out ISP on 38 x cisco 2911 routers. I have a cisco Mars device and i intend to setup logging on the routers so the IPS traffic will be logged to cisco mars.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cisco 2800 routers on the network but have been told that i need to upgrade them to 2911's to take advantage of the latest ios software needed for up to date signatures.&amp;nbsp; Not sure how accurate this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for a few hints to see if i am going about this the right way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a summary of the steps i think i need &lt;/P&gt;&lt;P&gt;1) Download IOS IPS signature package files and public crypto key from Cisco.com&lt;BR /&gt;2) configure the crypto key used by IOS IPS onto your Cisco 2911 router&lt;BR /&gt;3) Enable IOS IPS on the 2900 ROUTER (i have steps for this)&lt;/P&gt;&lt;P&gt;The plan is to Configure the IPS on a router using cisco SDM and the save this config to noetpad and paste it into all the routers out on site.&lt;/P&gt;&lt;P&gt;4) Load IOS IPS Signature packages to the router&lt;/P&gt;&lt;P&gt;5) Add the IP address of the routers into Cisco Mars and log traffic to cs mars device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prerequisites: CCO contract so i can get the signature updates from this site&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any advice is welcome&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:22:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667097#M64991</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2019-03-10T12:22:50Z</dc:date>
    </item>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667098#M64992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's take a step back. &lt;/P&gt;&lt;P&gt;First of all I geuss it's best to run this question by your SE(s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second of all considering you already own 2800 series you might look into getting AIM or NME IPS modules instead of swapping everything to 2900 and running IOS IPS. &lt;/P&gt;&lt;P&gt;Of course different pricing/throughput info apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AIM/NME IPS modules do not consume router's CPU and are in fact (logically) a separate device. &lt;/P&gt;&lt;P&gt;2900 have much more CPU/mem to burn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my experience, I have not found anyone recommending running IOS IPS in big deployment. Then again maybe I've not been talking to right people &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jun 2011 16:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667098#M64992</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-06-18T16:50:33Z</dc:date>
    </item>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667099#M64993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Marcin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What about CS Mars.&amp;nbsp; Have you heard of anyone using this product.&amp;nbsp; I thought the idea was to enable IPS on each router and push the syslog traffic back to the CS Mars device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2011 13:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667099#M64993</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2011-06-23T13:19:52Z</dc:date>
    </item>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667100#M64994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kevin, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MARS is used quite extensively, especially in enterprises. &lt;/P&gt;&lt;P&gt;That being said, I need to warn you. &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5739/ps6241/eol_c51-636888.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5739/ps6241/eol_c51-636888.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS can work no probelm in tandem with MARS, via different mechanisms. SDEE/traps/logs just to name a few.&lt;/P&gt;&lt;P&gt;Indeed the IOS IPS might be the cheaper of the solutions, in which case the more powerful hardware the better. &lt;/P&gt;&lt;P&gt;IPS appliances will usually provide a bit more features (global correlation) and separation of roles/hardware (to some extent). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2011 17:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667100#M64994</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-06-23T17:44:33Z</dc:date>
    </item>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667101#M64995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since you already have your MARS appliance, there would be no reason &lt;STRONG style="text-decoration: underline; "&gt;not&lt;/STRONG&gt; to use it for collection/correlation of your IOS-IPS events.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS Event retrieval (even for IOS IPS) is done by the MARS box using the SDEE protocol.&amp;nbsp; This is the same protocol/method used for communication with standalone IPS appliances.&amp;nbsp; This communication is separate from the syslog and/or SNMP reporting, which are used for the general router logging or monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, your router will be communicating with MARS using both SDEE (for IPS) and syslog/SNMP (or both).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Kevin O' Hare wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cisco 2800 routers on the network but have been told that i need&amp;nbsp; to upgrade them to 2911's to take advantage of the latest ios software&amp;nbsp; needed for up to date signatures.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you considering replacing your 28xx routers, or have the new routers already been purchased?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not clear in your original message whether or not you have already purchased the 2911 routers you mentioned.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that the person who provided this information was confusing IOS-IPS with the IPS modules (AIM-IPS, NME-IPS).&amp;nbsp; The AIM-IPS is only supported on the 28xx/38xx platform, using the IOS 12.4T release train.&amp;nbsp; The NME-IPS, however, is supported on both x8xx and x9xx platforms.&amp;nbsp; The 29xx routers will provide increased performance with IPS in IOS, but it's &lt;STRONG&gt;&lt;EM&gt;not a requirement&lt;/EM&gt;&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end, if you are talking about 38+ routers, adding modules might not be feasible.&amp;nbsp; Keep in mind that the software IPS takes up additional resources on the router.&amp;nbsp; If not configured properly, it can reduce performance, sometimes significantly.&amp;nbsp; Be cautious when rolling it out the feature, and closely monitor performance on your routers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jun 2011 01:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667101#M64995</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2011-06-24T01:40:24Z</dc:date>
    </item>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667102#M64996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running it on 16 sites with 2811 routers at the moment.&amp;nbsp; We are just pricing the 2911's but havent upgraded just yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So its IOS-IPS on the routers that i am interested in.&amp;nbsp; We dont have a seperate module on the router, we just role out the config for IPS, drop the signature file on the router and point it to cs mars.&amp;nbsp; Seems to be working so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q.&amp;nbsp;&lt;/P&gt;&lt;UL style="margin-top: 0cm;"&gt;&lt;LI&gt;I have download a recent signature package - &lt;STRONG&gt;IOS-S556-CLI.pkg&lt;/STRONG&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;I copied it to flash on a test router and I can access it via CLI or SDM&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;I have setup my router and put in all the config for IPS&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do i extract all the signatures from IOS-S556-CLI.pkg to an sdm file similar to 256MB SDF which has 500 signatures?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Router with IOS-S556-CLI.pkg&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;#sh ip ips signatures&lt;/P&gt;&lt;P&gt;Builtin signatures are configured&lt;/P&gt;&lt;P&gt;Signatures were last loaded from flash:/ips/IOS-S556-CLI.pkg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco SDF release version S0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Trend SDF release version V0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action=(A)larm,(D)rop,(R)eset,Deny-(H)ost,Deny-(F)low&lt;/P&gt;&lt;P&gt;*=Marked for Deletion WF=WantFrag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Trait=AlarmTraits&lt;/P&gt;&lt;P&gt;MH=MinHits&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AI=AlarmInterval&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CT=ChokeThreshold&lt;/P&gt;&lt;P&gt;TI=ThrottleInterval&amp;nbsp;&amp;nbsp; AT=AlarmThrottle&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FA=FlipAddr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Total Active Signatures: 0&lt;/P&gt;&lt;P&gt;Total Inactive Signatures: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if I change it back to &lt;STRONG&gt;Router with 256MB&lt;/STRONG&gt; I can see 537 signatures&lt;/P&gt;&lt;P&gt;#sh ip ips signatures&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;Builtin signatures are configured&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;Signatures were last loaded from flash:/ips/256MB.sdf&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;Cisco SDF release version 256MB.sdf V10&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;Total Active Signatures: 537&lt;/P&gt;&lt;P style="text-indent: -216pt; margin-left: 216pt;"&gt;Total Inactive Signatures: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 14:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667102#M64996</guid>
      <dc:creator>ohareka70</dc:creator>
      <dc:date>2011-07-01T14:36:14Z</dc:date>
    </item>
    <item>
      <title>Cisco IPS and  Cisco Mars rollout</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667103#M64997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Better Use AIM card that is more enogh for you i think and also MARS is already EOL So in future you have to change the logging as well.(Up to 2016 cisco support will be thr).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rajeswar.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 19:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ips-and-cisco-mars-rollout/m-p/1667103#M64997</guid>
      <dc:creator>haivrajesh</dc:creator>
      <dc:date>2011-07-01T19:27:41Z</dc:date>
    </item>
  </channel>
</rss>

