11-01-2006 12:55 AM - edited 03-10-2019 03:18 AM
Hi All,
I am new to ips ASA-SSM-10
First time logged into a ips module.
Can anyone give idea how to update the signatures.
Raj
Solved! Go to Solution.
11-01-2006 11:03 PM
Without licence you have fully functional IPS sensor but without latest signatures - its like running antivirus programm without updates - it can protect you from lot of attacks (using build in signatures, heuristic analyzies, protocol knowledge) but it doesnt protect you from latest attactks...
M.
11-01-2006 01:28 AM
ASA-SSM is running 5.x code so procedure is same like for stand alone IPS sensor (42xx)
First you need download signature file from
http://www.cisco.com/kobayashi/sw-center/ciscosecure/ids/crypto/
(you need licence for this)
more info
Upgrade procedure:
From CLI using upgrade command
From ASDM:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dmadmin.htm#wp1030863
You can also configure auto update
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/idmguide/dmadmin.htm#wp1030217
M.
Hope taht helps rate if it does
11-01-2006 08:26 PM
Hi,
Thanks for the info.
AS of now there is no liense in my ASA ssm
So what is the use of that box now ?
It is doing any ips function ?
Raj
11-01-2006 11:03 PM
Without licence you have fully functional IPS sensor but without latest signatures - its like running antivirus programm without updates - it can protect you from lot of attacks (using build in signatures, heuristic analyzies, protocol knowledge) but it doesnt protect you from latest attactks...
M.
11-08-2006 10:58 PM
Hi,
I have 2 questions :
How can I generate a report on all traffic blocked by the IPS?ASA 10 SSM since it was installed,traffic blocked by signatures.
When I do a sh event it is showing me a blank screen.
In Pix/ASA we have a syslog server that is able to generate all traffic that is passing through the firewall we can generate a report based on that .Is there something similar for IPS?ASA.
Where will I find the ip address of the IPS module .
I am trying to log in from Asdm to ips cant log in as I dont know where to find the ip address .I can log in through the telnet and ssh from the ASA
How can I access the event viewere and where will I know that it is installed to work for which Ip address.
raj
11-09-2006 10:06 PM
Hi,
Any ideas anyone ?
Raj
11-10-2006 08:26 AM
To get ip from ssm, log into ssm from asa console with "session 1"
Log into ssm and do show config, look for host-ip.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide