cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
913
Views
0
Helpful
3
Replies

management IP for sdee?

mulhollandm
Level 1
Level 1

folks

i've posted a query on this yesterday but i tried a couple of things and seem to have got further

if i point my collector (not mars) to the aip-ssm-20s management IP i get a connection and if i browse to it i can see the contents of the event store

Q1:

is this the correct configuration

Q2. Cisco IME shows i have 1700+ active signatures and 1688 enabled but when i ssh to the card and do a show conf or a more current i can only see
       the signatures below

       why!

signatures 1250 0
status
enabled true
exit
exit
signatures 2000 0
status
enabled true
exit
exit
signatures 2001 0
status
enabled true
exit
exit
signatures 2001 1
status
enabled true
exit   
exit
signatures 2001 2
status
enabled true
exit
exit
signatures 2002 0
status
enabled true
exit
exit
signatures 2003 0
status
enabled true
exit
exit
signatures 2004 0
status
enabled true
exit
exit
signatures 2005 0
status
enabled true
exit
exit
signatures 2006 0
status
enabled true
exit
exit
signatures 2007 0
status
enabled true
exit
exit
signatures 2008 0
status
enabled true
exit
exit
signatures 2009 0
status
enabled true
exit
exit
signatures 2010 0
status 
enabled true
exit
exit
signatures 2011 0
status
enabled true
exit
exit
signatures 2012 0
status
enabled true
exit
exit
signatures 2100 0
status
enabled true
exit
exit
signatures 3001 0
status
enabled true
exit
exit
signatures 3010 0
status
enabled true
exit
exit
signatures 3030 0
status
enabled true
exit
exit
signatures 4001 0
status
enabled true
exit
exit
signatures 4003 0
status
enabled true
exit
exit
exit     

thanks to anyone taking the time to reply

3 Replies 3

rhermes
Level 7
Level 7

Q1. Yes, you should always pull your SDEE events form the management IP address.

Q2. Only the signatures that differ from the default settings will appear in the "show confg" output, not all the signatures.

- Bob

Since you do not have an ip address on any other interface of the IPS there is no other way to connect on any other interface,

So yes you have done the right configuration.

Secondly

For any signature that has been tweeked as in modified in any way, including enabled, disabled or even retired so basically that is not in its default state will end up showing in the configuration.

So there is noting to worry about this.

Regards,

Sachin

sachin

again, many thanks for your contribution

greatly appreciated

Review Cisco Networking for a $25 gift card