cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

495
Views
0
Helpful
1
Replies
Highlighted
Beginner

Deleted Custom Signature still triggering

Working with an ASA5555-IPS, running ver: 7.1(6)E4, latest sigs, doing some initial testing.

I created a custom signature in the default sig0 to do some testing. sig id was 60000.

I then "disabled" it in the IME and hit apply, took a few seconds, double checked the list, and the signature was now listed as disabled.

Did testing again, and this disabled signature was still triggering.

Then I retired it, hit apply.

Did testing again, and this now disabled and retired signature was still triggering.

Now I deleted the signature.

Testing, still triggering.

Now I made a new signature with same sig id.

Testing, still triggering old signature.

The only way I could make this stop, was to reboot the sensor.

Is there a signature cache or something like that? Is there a way to clear it, or rebuild it on demand?

1 REPLY 1
Highlighted
Beginner

Is it possible to try the steps with IPS CLI interface.

Under "service sig-def ", issue "no signature 60000 0" and Apply.

Otherwise it looks like a bug, you may want to report it to Cisco TAC and get this fixed in the newer release.

Regards,

Sawan Gupta

Thanks & Regards, Sawan Gupta
Content for Community-Ad