<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with v5.x signatures in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856376#M85712</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to enable IOS IPS on my 7204-G2 router but have few problems.I use IOS c7200p-adventerprisek9-mz.124-15.T1 and signatures IOS-S297-CLI.I use this doc &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0080747eb0.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0080747eb0.html&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first time when I try to "copy t&lt;A class="jive-link-custom" href="ftp://x.x.x.x/IOS-S297-CLI.pkg" target="_blank"&gt;ftp://x.x.x.x/IOS-S297-CLI.pkg&lt;/A&gt; idconf" the compilation process is susses but I have this messages: %IPS-4-SIGNATURE_COMPILE_FAILURE , %IPS-4-META_ENGINE_UNSUPPORTED ,  %IPS-4-SDF_PARSE_FAILED: file disk2:myips/7204-sigdef-default.xml. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this I have few .xml files in my folder disk2:/myips/,but when I try to active ips on interface all the traffic stops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the second try after "copy t&lt;A class="jive-link-custom" href="ftp://x.x.x.x/IOS-S297-CLI.pkg" target="_blank"&gt;ftp://x.x.x.x/IOS-S297-CLI.pkg&lt;/A&gt; idconf" traffic stops and then router go to reboot.In folder disk2:/myips/ at this time I have more files,but after "ip ips myips in" traffic stops again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What the problem with signatures compilation? Maybe this is a bug in IOS or something.   &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:47:50 GMT</pubDate>
    <dc:creator>seducer666</dc:creator>
    <dc:date>2019-03-10T10:47:50Z</dc:date>
    <item>
      <title>Problem with v5.x signatures</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856376#M85712</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to enable IOS IPS on my 7204-G2 router but have few problems.I use IOS c7200p-adventerprisek9-mz.124-15.T1 and signatures IOS-S297-CLI.I use this doc &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0080747eb0.html" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0080747eb0.html&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At first time when I try to "copy t&lt;A class="jive-link-custom" href="ftp://x.x.x.x/IOS-S297-CLI.pkg" target="_blank"&gt;ftp://x.x.x.x/IOS-S297-CLI.pkg&lt;/A&gt; idconf" the compilation process is susses but I have this messages: %IPS-4-SIGNATURE_COMPILE_FAILURE , %IPS-4-META_ENGINE_UNSUPPORTED ,  %IPS-4-SDF_PARSE_FAILED: file disk2:myips/7204-sigdef-default.xml. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this I have few .xml files in my folder disk2:/myips/,but when I try to active ips on interface all the traffic stops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the second try after "copy t&lt;A class="jive-link-custom" href="ftp://x.x.x.x/IOS-S297-CLI.pkg" target="_blank"&gt;ftp://x.x.x.x/IOS-S297-CLI.pkg&lt;/A&gt; idconf" traffic stops and then router go to reboot.In folder disk2:/myips/ at this time I have more files,but after "ip ips myips in" traffic stops again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What the problem with signatures compilation? Maybe this is a bug in IOS or something.   &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856376#M85712</guid>
      <dc:creator>seducer666</dc:creator>
      <dc:date>2019-03-10T10:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with v5.x signatures</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856377#M85713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are getting these errors because you are trying to compile all signatures at a single go, which is not recommended. The v5&lt;/P&gt;&lt;P&gt;style signatures are common to the IOS IPS and the IDS/IPS sensor appliances but IOS IPS does not support all of the signature engines (hence the META_ENGINE_UNSUPPORTED errors) and most IOS platforms will not have sufficient CPU and memory resources to compile *all* the supported ones.  In other words, the behavior you experienced is normal, the solution is to start with retiring all signature categories and then gradually enable those you need. Following link may help you&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0080747eb0.html#wp1064428" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a0080747eb0.html#wp1064428&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2007 20:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856377#M85713</guid>
      <dc:creator>amritpatek</dc:creator>
      <dc:date>2007-09-19T20:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with v5.x signatures</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856378#M85715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;I read the manual twice and fined solution to correct using 5.x signatures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok,IPS work ,but I have few questions.&lt;/P&gt;&lt;P&gt;With working IPS my G2 have 70% cpu usage,and I must turn on IPS only for few networks,when I use 4.x IPS I use access-list "ip ips name myips list 141" ,it looks like: &lt;/P&gt;&lt;P&gt;"10 permit ip 192.168.3.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt; 20 permit ip any 192.168.3.0 255.255.255.0"&lt;/P&gt;&lt;P&gt;Everething work fine,IPS working only for network 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now with 5.x IPS I try use the same access-list but when I turn IPS on the interface all the traffic stops. Without access-list all working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2007 04:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-v5-x-signatures/m-p/856378#M85715</guid>
      <dc:creator>seducer666</dc:creator>
      <dc:date>2007-09-26T04:43:25Z</dc:date>
    </item>
  </channel>
</rss>

