<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS: relationship between signatures and network service in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942090#M79748</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not aware of any such recommendation or profile available on the IPS based on services deployed. But within the IPS you can arrange the current signatures 'view' based on Engines/Categories/Protocols etc. and you can use that functionality to disable/enable multiple signatures in one go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/idm/idm_signature_definitions.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/idm/idm_signature_definitions.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Jun 2008 01:18:07 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-06-12T01:18:07Z</dc:date>
    <item>
      <title>IPS: relationship between signatures and network service</title>
      <link>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942089#M79744</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know if there is documentation regarding the recommended signatures to be activated depending of the network service being deployed?&lt;/P&gt;&lt;P&gt;Let's say that I have several servers behind a firewall, therefore, in theory I would only need to activate in my IPS the signatures related to those services, for example, ftp, https, aaa, etc...&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942089#M79744</guid>
      <dc:creator>javiercastro</dc:creator>
      <dc:date>2019-03-10T11:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: IPS: relationship between signatures and network service</title>
      <link>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942090#M79748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not aware of any such recommendation or profile available on the IPS based on services deployed. But within the IPS you can arrange the current signatures 'view' based on Engines/Categories/Protocols etc. and you can use that functionality to disable/enable multiple signatures in one go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/idm/idm_signature_definitions.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/idm/idm_signature_definitions.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jun 2008 01:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942090#M79748</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-12T01:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPS: relationship between signatures and network service</title>
      <link>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942091#M79751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on IPS, you should be able to disable signatures for Solaris, OSX, Windows, Linux if you are not using them in your network. The trick is getting the vendor to admit how many signatures the device can handle. They will almost always lye to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you but sensors in front and behind your firewalls. You will see which are getting through the firewall, That then need to be install on the IPS to protect against.. if you add a 3rd sensor in back of the IPS. you can see how many made it past all your defenses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps a little.&lt;/P&gt;&lt;P&gt;~TS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Jul 2008 14:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-relationship-between-signatures-and-network-service/m-p/942091#M79751</guid>
      <dc:creator>TradeSecrets</dc:creator>
      <dc:date>2008-07-11T14:21:55Z</dc:date>
    </item>
  </channel>
</rss>

