cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
723
Views
0
Helpful
1
Replies

Deleted Custom Signature still triggering

cds-cisco
Level 1
Level 1

Working with an ASA5555-IPS, running ver: 7.1(6)E4, latest sigs, doing some initial testing.

I created a custom signature in the default sig0 to do some testing. sig id was 60000.

I then "disabled" it in the IME and hit apply, took a few seconds, double checked the list, and the signature was now listed as disabled.

Did testing again, and this disabled signature was still triggering.

Then I retired it, hit apply.

Did testing again, and this now disabled and retired signature was still triggering.

Now I deleted the signature.

Testing, still triggering.

Now I made a new signature with same sig id.

Testing, still triggering old signature.

The only way I could make this stop, was to reboot the sensor.

Is there a signature cache or something like that? Is there a way to clear it, or rebuild it on demand?

1 Reply 1

sawgupta
Level 1
Level 1

Is it possible to try the steps with IPS CLI interface.

Under "service sig-def ", issue "no signature 60000 0" and Apply.

Otherwise it looks like a bug, you may want to report it to Cisco TAC and get this fixed in the newer release.

Regards,

Sawan Gupta

Thanks & Regards, Sawan Gupta
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card