<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco version 6 and analysis engines in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889335#M85222</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've run 2 successfully, but I suspect it depends a great deal on the actual policy configuration and traffic patterns. In our case,  in a 4255 we saw memory consumption remain about the same (~50%) but CPU went from about 30-45% to 50-65%.  If that holds for a 3rd set of policies (CPU ~70-85%), I personally wouldn't do it, but YMMV.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 27 Nov 2007 14:43:26 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2007-11-27T14:43:26Z</dc:date>
    <item>
      <title>Cisco version 6 and analysis engines</title>
      <link>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889334#M85220</link>
      <description>&lt;P&gt;Looking for information on how many instances of "rulesx" and "sigx" can be run on the different platforms? Example I can configure rules0, rules1, rules2 and the same for sig0, sig1 and sig2, but how many can I do? &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889334#M85220</guid>
      <dc:creator>5creedus</dc:creator>
      <dc:date>2019-03-10T10:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco version 6 and analysis engines</title>
      <link>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889335#M85222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've run 2 successfully, but I suspect it depends a great deal on the actual policy configuration and traffic patterns. In our case,  in a 4255 we saw memory consumption remain about the same (~50%) but CPU went from about 30-45% to 50-65%.  If that holds for a 3rd set of policies (CPU ~70-85%), I personally wouldn't do it, but YMMV.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 14:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889335#M85222</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-11-27T14:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco version 6 and analysis engines</title>
      <link>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889336#M85226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Generally you are limited to 4 virtual sensor configurations..vs0 and up to 3 additional named virtual sensors, such as vs1, "this_sensor", and "that_sensor" (see an exception in the next paragraph).  The number of defined components (sigX, rulesX, adX) is not capped, but a maximum of 4 will be active at any time...corresponding to the virtual sensors.  It should be noted that you can reuse components, e.g. sig0 can be used in both vs0 and vs2 while sig1 is used in vs1.  The same for rulesX and adX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a limitation on the "low memory" sensors, currently the 4215 and NM-CIDS, of a single active virutal sensor.  These low end sensors do not have the memory capacity to keep multiple configurations active in memory and still meet performance standards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 15:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889336#M85226</guid>
      <dc:creator>scothrel</dc:creator>
      <dc:date>2007-11-27T15:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco version 6 and analysis engines</title>
      <link>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889337#M85230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks all, both responses helped&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Nov 2007 16:48:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-version-6-and-analysis-engines/m-p/889337#M85230</guid>
      <dc:creator>5creedus</dc:creator>
      <dc:date>2007-11-27T16:48:42Z</dc:date>
    </item>
  </channel>
</rss>

