<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IOS IPS Automatic Signature Update in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447535#M66818</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sid-san,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I,m sorry interrupt you. &lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;I heard from your engineer. He said "IOS-IPS is able to update IPS's signature automatically, if &lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;IOS-IPS version is 5.x or later. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/routers/access/1900/software/configuration/guide/Secconf1_ps10538_TSD_Products_Configuration_Guide_Chapter.html#wp1055483"&gt;http://www.cisco.com/en/US/docs/routers/access/1900/software/configuration/guide/Secconf1_ps10538_TSD_Products_Configuration_Guide_Chapter.html#wp1055483&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;Pls confirm it and advise me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-fareast-language: JA; mso-spacerun: yes; mso-hansi-font-family: Arial; mso-fareast-font-family: 'ＭＳ Ｐゴシック'; "&gt;Regard,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-fareast-language: JA; mso-spacerun: yes; mso-hansi-font-family: Arial; mso-fareast-font-family: 'ＭＳ Ｐゴシック'; "&gt;Kise&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Aug 2010 10:52:34 GMT</pubDate>
    <dc:creator>info.kise</dc:creator>
    <dc:date>2010-08-17T10:52:34Z</dc:date>
    <item>
      <title>IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447529#M66794</link>
      <description>&lt;P&gt;I will use cisco1941w.&lt;/P&gt;&lt;P&gt;I'd like to know, how to configure at CLI and where is the URL.&lt;/P&gt;&lt;P&gt;Is the bellow correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CLI&lt;/P&gt;&lt;P&gt;Router(config)# ip ips auto-update&lt;BR /&gt;Router(config-ips-auto-update)# occur-at 0 0-23 1-31 1-5&lt;/P&gt;&lt;P&gt;Router(config-ips-auto-update)# url &lt;SPAN class="cXRef_Color" style="font-weight: normal;"&gt;&lt;A href="https://www.cisco.com/cgi-bin/front.x/ida/locator/locator.pl" target="_blank"&gt;https://www.cisco.com/cgi-bin/front.x/ida/locator/locator.pl&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Router(config-ips-auto-update)# username XXX password XXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;URL&lt;/P&gt;&lt;P&gt;&lt;SPAN class="cXRef_Color" style="font-weight: normal;"&gt;&lt;A href="https://www.cisco.com/cgi-bin/front.x/ida/locator/locator.pl" target="_blank"&gt;https://www.cisco.com/cgi-bin/front.x/ida/locator/locator.pl&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447529#M66794</guid>
      <dc:creator>iotoiotoioto</dc:creator>
      <dc:date>2019-03-10T12:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447530#M66797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. Currently IOS-IPS does not have the functionality to have auto-signature updates from cisco.com like IPS appliances and modules do.&lt;/P&gt;&lt;P&gt;Hence there is no url on cisco.com for auto-signatures updates for IOS-IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b. You can have your own HTTP/TFTP server where you can keep all the IPS signatures downloaded from cisco.com The IOS-IPS can grab files from this server. The configuration you are referring to this part of the configuration where you specify the HTTP/TFTP server address and login credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c. Alternatively, the same configuration can be done by CCP (IOS-IPS configuration is less cumbersome via CCP). Attaching a screenshot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;TAC Security Solutions&lt;/P&gt;&lt;P&gt;Customer Support Engineer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 17:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447530#M66797</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2010-08-12T17:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447531#M66801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much, Sid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to ask more.&lt;/P&gt;&lt;P&gt;How to set up IOS IPS by CCP.&lt;/P&gt;&lt;P&gt;Does it need signature before configuration?&lt;/P&gt;&lt;P&gt;I'like to configure Automatic-Update(IPS signature) by CCP at leaset. Is it possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or can I configure by any other soft without signature?&lt;/P&gt;&lt;P&gt;I can't download CSM. Becase of license.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 11:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447531#M66801</guid>
      <dc:creator>iotoiotoioto</dc:creator>
      <dc:date>2010-08-13T11:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447532#M66803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. IOS-IPS is a software feature on IOS. It can be configured on the router via CLI or CCP.&lt;/P&gt;&lt;P&gt;So auto-signature update via cisco.com which is not available for IOS-IPS will not be possible even via CCP.&lt;/P&gt;&lt;P&gt;The screenshot in my last post shows how to setup auto-signature update for IOS-IPS from a tftp server in your network.&lt;/P&gt;&lt;P&gt;You will still have to manually download signatures from cisco.com and put them on the tftp server. The router will simply grab &amp;amp; install the signature file from the tftp server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Configuring IOS-IPS via CCP:&lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/squish/c8f28" id="ext-gen223" onclick=""&gt;http://tools.cisco.com/squish/c8f28&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. CCP is free. No license needed. You can download CCP as long as you have valid cisco.com username and password.&lt;/P&gt;&lt;P&gt;Download link for CCP:&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://tools.cisco.com/squish/a2CA0" id="ext-gen223" onclick=""&gt;http://tools.cisco.com/squish/a2CA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;TAC Security Solutions&lt;/P&gt;&lt;P&gt;Customer support engineer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Aug 2010 19:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447532#M66803</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2010-08-13T19:20:12Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447533#M66805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Sorry, &lt;/SPAN&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;I made mistake you to question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Firsttime, I already used CCP, but I couldn't configure anything IPS by CCP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So I resarched and asked something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could I ask you final?&lt;/P&gt;&lt;P&gt;I couldn't configure IOS-IPS by CCP.&lt;/P&gt;&lt;P&gt;I think because of I don't have signature, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by the way, I couldn't understand your screenshot, because it's not clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Aug 2010 06:14:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447533#M66805</guid>
      <dc:creator>iotoiotoioto</dc:creator>
      <dc:date>2010-08-14T06:14:33Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447534#M66808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you follow the link below step-by-step, then you should be able to configure IOS-IPS via CCP.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small active_link" href="http://tools.cisco.com/squish/c8f28"&gt;http://tools.cisco.com/squish/c8f28&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure why the screenshot attached is not correctly viewable for you.&lt;/P&gt;&lt;P&gt;It only shows the&amp;nbsp; the section on CCP where you configure auto-sig update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, the link I mentioned has appropriate screenshots for CCP configuration of IOS-IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Sid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Aug 2010 18:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447534#M66808</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2010-08-15T18:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447535#M66818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sid-san,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I,m sorry interrupt you. &lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;I heard from your engineer. He said "IOS-IPS is able to update IPS's signature automatically, if &lt;/SPAN&gt;&lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;IOS-IPS version is 5.x or later. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/routers/access/1900/software/configuration/guide/Secconf1_ps10538_TSD_Products_Configuration_Guide_Chapter.html#wp1055483"&gt;http://www.cisco.com/en/US/docs/routers/access/1900/software/configuration/guide/Secconf1_ps10538_TSD_Products_Configuration_Guide_Chapter.html#wp1055483&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="mso-fareast-font-family: 'ＭＳ Ｐゴシック'; mso-fareast-language: JA; mso-hansi-font-family: Arial;"&gt;Pls confirm it and advise me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-fareast-language: JA; mso-spacerun: yes; mso-hansi-font-family: Arial; mso-fareast-font-family: 'ＭＳ Ｐゴシック'; "&gt;Regard,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="mso-fareast-language: JA; mso-spacerun: yes; mso-hansi-font-family: Arial; mso-fareast-font-family: 'ＭＳ Ｐゴシック'; "&gt;Kise&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 10:52:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447535#M66818</guid>
      <dc:creator>info.kise</dc:creator>
      <dc:date>2010-08-17T10:52:34Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447536#M66819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Were experiancing the same challenges with the IOS-auto-update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have set up an external FTP server with the latest .PKG. We download it from cisco.com and then rename it to a generic name (ips.pkg). In our router config, we have deployed this config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip ips auto-update&lt;BR /&gt; occur-at 1 0-23 1-31 0-6&lt;BR /&gt;&lt;SPAN&gt; url &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://172.22.85.29/ips.pkg"&gt;ftp://172.22.85.29/ips.pkg&lt;/A&gt;&lt;BR /&gt; username ips password xxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have 400 branch routers (1811) that are configured to go get this update once, every hour. At our Head-office we restrict the access with time-based ACL that restrict the update to occurs only at specific time of the day/week. We are doing so because we found out that the mecanism to control the time access on the router is not working well we had to find out a other way to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The big problem is that with this method, the router is downloading a 10 Meg file. When you have 400 branch routers connected centrally, it means 400 routers downloading a 10 meg file at the same time is impacting your network big time and so your FTP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With IOS 12.4T, the IOS IPS is creating 6 .XML files from the .PKG file. Those files are named with the hostname of the router and so unsusable for large-scale deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With IOS 15.0M, the IOS IPS is creating 6 .XMZ files, without using the hostname of the router. therefore we could use directly the .XMZ file as our config. the XMZ file are quite small compared to the 10 Meg PKG files and we could use it directly on our FTP server. We could configure only one router to manage our signatures, download the big PKG file to it, update the signatures on it, manage the signatures on it and then pick the .XMZ file and copy it to our central FTP server which will feed all our other routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the config would look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip ips auto-update&lt;BR /&gt;&amp;nbsp; occur-at 1 0-23 1-31 0-6&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; url &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://172.22.85.29/filename.xmz"&gt;ftp://172.22.85.29/filename.xmz&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; username ips password xxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This could limit the seize of the tranfert and therefore greatly improves the managability of the whole process without having any impact on our WAN links.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My only question. What is the .XMZ or XML file we need to use !! they are 6 of them and the router let us use only one in the configuration ?!!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never found any answer on this. Can somebody help me with that !?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Aug 2010 13:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447536#M66819</guid>
      <dc:creator>nicolas.bedard</dc:creator>
      <dc:date>2010-08-18T13:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447537#M66823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;A. Hete is what the six files do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pBulletCMT" style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 3pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-transform: none;"&gt;• &lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;ios-ips-sigdef-default.xml:&lt;/SPAN&gt; contains all the factory default signature definitions&lt;/P&gt;&lt;A name="wp9000231"&gt;&lt;/A&gt;&lt;P class="pBulletCMT" style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 3pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-transform: none;"&gt;• &lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;ios-ips-sigdef-delta.xml:&lt;/SPAN&gt; contains signature definitions that have been changed from the default&lt;/P&gt;&lt;A name="wp9000232"&gt;&lt;/A&gt;&lt;P class="pBulletCMT" style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 3pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-transform: none;"&gt;• &lt;SPAN class="content"&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;ios-ips&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;-sigdef-typedef.xml:&lt;/SPAN&gt; is a file that has all the signature parameter definitions&lt;/P&gt;&lt;A name="wp9000233"&gt;&lt;/A&gt;&lt;P class="pBulletCMT" style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 3pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-transform: none;"&gt;• &lt;SPAN class="content"&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;ios-ips&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;-sigdef-category.xml:&lt;/SPAN&gt; has all the signature category information, such as category ios_ips basic and advanced&lt;/P&gt;&lt;A name="wp9000234"&gt;&lt;/A&gt;&lt;P class="pBulletCMT" style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 3pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-transform: none;"&gt;• &lt;SPAN class="content"&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;ios-ips&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;-seap-delta.xml:&lt;/SPAN&gt; contains changes made to the default SEAP parameters&lt;/P&gt;&lt;A name="wp9000235"&gt;&lt;/A&gt;&lt;P class="pBulletCMT" style="font-style: normal; font-variant: normal; font-weight: normal; margin-bottom: 3pt; margin-right: 0pt; margin-top: 0pt; text-decoration: none; text-transform: none;"&gt;• &lt;SPAN class="content"&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;ios-ips&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="cCMTDefault" style="font-style: normal; font-weight: bold;"&gt;-seap-typedef.xml:&lt;/SPAN&gt; contains all the SEAP parameter definitions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;B. So the signature file (.pkg) is decompressed into these files and then 'idconf' loads them in memory.&lt;/P&gt;&lt;P&gt;Hence to copy signature database of one router to the other, we need to copy atleast first 4 files.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;You only need to distribute the SEAP configuration if you modified any of the Signature Event Action Override configuration:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We do not have one single file that contains all the signatures.&amp;nbsp; The signature package is installed in a certain way.&lt;/P&gt;&lt;P&gt;Hence we will need atleast first 4 files to copy of signature database from one router to the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C. Secondly, I dont know if auto-update will accept a file in .xmz package, I have not tested this.&lt;/P&gt;&lt;P&gt;But I am guessing it will look for a .pkg file and decompress it.&lt;/P&gt;&lt;P&gt;With copying a .xmz file, you may have to manually load it into memory using 'idconf' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;D. Hence there is no one single configuration file that you copy off the external ftp server.&lt;/P&gt;&lt;P&gt;I guess, the only thing you can do is to have different routers update signatures at different times to reduce load on the network.&lt;/P&gt;&lt;P&gt;It is also not necessary to check for signature updates every hour.&lt;/P&gt;&lt;P&gt;Normal rate of adding new signature releases is every few days, so even if you check around once a day that should be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;TAC Security Solutions&lt;/P&gt;&lt;P&gt;Customer support engineer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Aug 2010 16:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447537#M66823</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2010-08-18T16:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: IOS IPS Automatic Signature Update</title>
      <link>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447538#M66826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following &lt;A href="http://www.cisco.com/en/US/docs/ios/sec_data_plane/configuration/guide/sec_ips5_sig_fs_ue.html#wp1137583"&gt;document seems to suggest that signature auto-update from cisco.com is possible&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't tested this myself but it looks like the feature is there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 06:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ios-ips-automatic-signature-update/m-p/1447538#M66826</guid>
      <dc:creator>Nicolas Meessen</dc:creator>
      <dc:date>2010-10-29T06:40:09Z</dc:date>
    </item>
  </channel>
</rss>

