10-16-2008 11:13 AM - edited 03-10-2019 04:19 AM
Hi all,
with Cisco Service for IPS active my IPS that run in ASA module will be able to download the signatures on Cisco`s Web site and update them alone?
thanks for your help. "Together we are even better"
Solved! Go to Solution.
10-16-2008 05:41 PM
Yes, If you are running IPS 6.1(1) you can configure a schedule on the sensor to check for any signature updates on CCO , download and install them.
10-16-2008 05:41 PM
Yes, If you are running IPS 6.1(1) you can configure a schedule on the sensor to check for any signature updates on CCO , download and install them.
10-18-2008 01:11 PM
But please note that even tough its 'possible', its always better to do this manually. Sometimes some signatures generate a lot of false positives and its a good idea to check here on netpro and other places for any problems others are facing before applying signature updates (in production). However most signatures only produce alerts, so its just the noise that will worry ya and 'usually' signature updates don't break anything on the network.
Regards
Farrukh
10-18-2008 06:03 PM
Farrukh, Tks for you answer!!!
Could you explain me better why the signature update usually dont break anything? All this (security world) is very new for me.
Thanks you so much
Rodrigo Alves
10-18-2008 09:40 PM
Rodrigo that is the case because Cisco usually keeps signatures to only 'Product Alert' by default, and no block/deny actions are performed. The only notable exception is the TCP normalization engine.
Regards
Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide