<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enable IPS IPS/IDS in cisco 2811 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239399#M77277</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ribin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attack-drop.sdf is the basic signature file. You need to download 128MB.sdf or 256MB.sdf, which is also in SDM disk. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ip ips sdf location " command is for 18XX router&lt;/P&gt;&lt;P&gt;use the following command for 28xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip ips config location flash://128MB.sdf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H2H&lt;/P&gt;&lt;P&gt;Roshan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 19 Apr 2009 11:05:48 GMT</pubDate>
    <dc:creator>roshan.maskey</dc:creator>
    <dc:date>2009-04-19T11:05:48Z</dc:date>
    <item>
      <title>How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239395#M77273</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a Cisco 2811 with IOS Version 12.4(20)T and I need to enable IPS or IDS in this. What is the config for this?&lt;/P&gt;&lt;P&gt;First of all, I need to know whether I can do IPS/IDS in my router as well..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ribin&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239395#M77273</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2019-03-10T11:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239396#M77274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ribin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Router supports IOS IPS 5.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the sample configuration:&lt;/P&gt;&lt;P&gt;Step 1: Verify if you have signature file (128MB.sdf or 256MB.sdf)&lt;/P&gt;&lt;P&gt;router# sh flash&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step2: Specify router to use sig-definition file&lt;/P&gt;&lt;P&gt;router(config)# ip ips sdf location flash://128MB.sdf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step3: create signature_rule&lt;/P&gt;&lt;P&gt;router(config)# ip ips name myips_rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step4: Apply IPS rule to interface&lt;/P&gt;&lt;P&gt;router(config)# interface fa0/0&lt;/P&gt;&lt;P&gt;router(config-if)# ip ips myips_rule in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step5: Enable IPS SDEE notification&lt;/P&gt;&lt;P&gt;router(config)# ip ips notify sdee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can further tune IPS signature using SDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H2H&lt;/P&gt;&lt;P&gt;Roshan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Apr 2009 10:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239396#M77274</guid>
      <dc:creator>roshan.maskey</dc:creator>
      <dc:date>2009-04-19T10:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239397#M77275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have 128MB.sdf or 256MB.sdf. But I do have a attack-drop.sdf. Any idea what it might be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Apr 2009 10:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239397#M77275</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2009-04-19T10:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239398#M77276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I see the below from my config prompt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)#ip ips ?&lt;/P&gt;&lt;P&gt;  auto-update           Auto Update&lt;/P&gt;&lt;P&gt;  config                Location of IPS configuration files&lt;/P&gt;&lt;P&gt;  deny-action           Specify Deny action&lt;/P&gt;&lt;P&gt;  event-action-rules    Event Action Rules (SEAP)&lt;/P&gt;&lt;P&gt;  fail                  Specify what to do during any failures&lt;/P&gt;&lt;P&gt;  name                  Specify an IPS rule&lt;/P&gt;&lt;P&gt;  notify                Specify the notification mechanisms (SDEE or log) for&lt;/P&gt;&lt;P&gt;                        the alarms&lt;/P&gt;&lt;P&gt;  signature-category    Signature Category&lt;/P&gt;&lt;P&gt;  signature-definition  Signature Definition&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see &lt;/P&gt;&lt;P&gt;ips sdf command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Apr 2009 10:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239398#M77276</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2009-04-19T10:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239399#M77277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ribin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attack-drop.sdf is the basic signature file. You need to download 128MB.sdf or 256MB.sdf, which is also in SDM disk. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"ip ips sdf location " command is for 18XX router&lt;/P&gt;&lt;P&gt;use the following command for 28xx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip ips config location flash://128MB.sdf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H2H&lt;/P&gt;&lt;P&gt;Roshan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Apr 2009 11:05:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239399#M77277</guid>
      <dc:creator>roshan.maskey</dc:creator>
      <dc:date>2009-04-19T11:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239400#M77278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did enabled IPS in the router and configured to notify to our log server. Below is the log I received in my log server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does IPS does now and what kind of logs I can expect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ribin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 19 14:53:38 192.168.11.10 4546: *Apr 19 09:27:41.254: %SYS-5-CONFIG_I: Configured from console by ribin on vty0 (192.168.11.35)&lt;/P&gt;&lt;P&gt;Apr 19 18:04:29 192.168.11.10 4548: *Apr 19 12:38:32.601: %CRYPTO-6-IPSEC_USING_DEFAULT: IPSec is using default transforms&lt;/P&gt;&lt;P&gt;Apr 19 18:12:10 192.168.11.10 4549: *Apr 19 12:46:14.541: %IPS-6-ENGINE_BUILDS_STARTED:  12:46:14 UTC Apr 19 2009&lt;/P&gt;&lt;P&gt;Apr 19 18:12:10 192.168.11.10 4550: *Apr 19 12:46:14.541: %IPS-6-ENGINE_BUILDING: atomic-ip - 3 signatures - 1 of 13 engines&lt;/P&gt;&lt;P&gt;Apr 19 18:12:10 192.168.11.10 4551: *Apr 19 12:46:14.557: %IPS-6-ENGINE_READY: atomic-ip - build time 16 ms - packets for this engine will be scanned&lt;/P&gt;&lt;P&gt;Apr 19 18:12:10 192.168.11.10 4552: *Apr 19 12:46:14.557: %IPS-6-ALL_ENGINE_BUILDS_COMPLETE: elapsed time 16 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Apr 2009 11:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239400#M77278</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2009-04-19T11:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239401#M77279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I see the following error in my log server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%IPS-3-IPS_FILE_OPEN_ERROR: flash://128MB.sdf/Router11.10-seap-typedef.xml - Requested operation requires a directory&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Apr 2009 13:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239401#M77279</guid>
      <dc:creator>ribin.jones</dc:creator>
      <dc:date>2009-04-19T13:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable IPS IPS/IDS in cisco 2811</title>
      <link>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239402#M77280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The recommendation to use the 128MB.sdf or 256MB.sdf is not correct for the version of software that you're using.  IOS 12.4(11)T and later use the v5 signatures, available here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/ios-v5sigup" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/ios-v5sigup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a video demonstration describing the use of Cisco Configuration Professional for IPS, here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cdc_content_elements/flash/ios/configios/index.html" target="_blank"&gt;http://www.cisco.com/cdc_content_elements/flash/ios/configios/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CLI configuration guide is here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ips_v5.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ips_v5.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be sure that you configure the IPS to load the 'ios_ips basic' or 'ios_ips advanced' categories.  If the router tries to load the default signatures, it will run out of memory and crash.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2009 20:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-enable-ips-ips-ids-in-cisco-2811/m-p/1239402#M77280</guid>
      <dc:creator>bstiff</dc:creator>
      <dc:date>2009-05-06T20:16:39Z</dc:date>
    </item>
  </channel>
</rss>

