cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
941
Views
0
Helpful
3
Replies

Problem updating signature updates in IDS 4215

talha_490
Level 1
Level 1

Problem upgrading the signatures of IDS 4215

I have to upgrade the signature file of ids 4215. The latest signature update version is IDS-sig-4.1-5-S252. To upgrade the signature file I install the service pack IDS-K9-sp-4.1-5-S189. The service pack was installed properly but while updating the signatures it is giving the following error

Error: Cannot communicate with mainApp (getVersion). Please contact your system

Administrator.

Would you like to run cidDump? [No]:

Procedure Followed

I installed a ftp server in the network and put the signature update file there. I then issued the command

upgrade ftp://administrator@191.10.50.31/5Dp--5-S2s52.ir

Pmg.pk-g4.1-5-S252.rpm.pkg

After that it gave me the above error

Question

How can I recover the image while recovery partition is already there?

The snapshot of the procedure that I followed is given below

login: cisco

Password:

***NOTICE***

This product contains cryptographic features and is subject to United States

and local country laws governing import, export, transfer and use. Delivery

of Cisco cryptographic products does not imply third-party authority to import,

export, distribute or use encryption.

http://www.cisco.com/wwl/export/crypto

If you require further assistance please contact us by sending email to

export@cisco.com.

customer-ids4215#

customer-ids4215# sh ver

customer-ids4215# sh version

Application Partition:

Cisco Systems Intrusion Detection Sensor, Version 4.1(5)S189

OS Version 2.4.26-IDS-smp-bigphys

Platform: IDS-4215

Using 424386560 out of 460161024 bytes of available memory (92% usage)

Using 4.4G out of 17G bytes of available disk space (27% usage)

MainApp 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

AnalysisEngine 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

Authentication 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

Logger 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

NetworkAccess 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

TransactionSource 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

WebServer 2005_Sep_01_21.30 (Release) 2005-09-01T21:30:35-0500 R

unning

CLI 2005_Aug_02_10.53 (Release) 2005-08-02T10:25:35-0500

Upgrade History:

* IDS-sig-4.1-4-S119 17:29:28 UTC Sat Oct 16 2004

IDS-K9-sp-4.1-5-S189.rpm.pkg 09:28:03 UTC Wed Dec 27 2006

Recovery Partition Version 2.4 - 4.1(4)S91

customer-ids4215#

customer-ids4215#

customer-ids4215# conf t

customer-ids4215(config)#

customer-ids4215(config)# upgrade

<source-url> Location of upgrade

customer-ids4215(config)# upgrade ftp://administrator@191.10.50.31/5Dp--5-S2s52.ir

pmg.pk-g4.1-5-S252.rpm.pkg

Password:

Warning: Executing this command will apply a signature update to the application

partition.

Continue with upgrade? : yes

Broadcast message from root (Sun Jan 7 14:46:24 2007):

Applying update IDS-sig-4.1-5-S252. This may take several minutes.

Please do not reboot the sensor during this update.

login: cisco

Password:

***NOTICE***

This product contains cryptographic features and is subject to United States

and local country laws governing import, export, transfer and use.http://www.cisco.com/wwl/export/crypto

If you require further assistance please contact us by sending email to

export@cisco.com.

Error: Cannot communicate with mainApp (getVersion). Please contact your system

administrator.

Would you like to run cidDump?[no]:

Connection to host lost.

C:\>

3 Replies 3

chickman
Level 1
Level 1

Just so you know, you will need to update your IPS from 4.1-5 to 5.0-1 to get signatures up to 217. To get a signature beyond 217, you'll need to upgrade to 5.0-5. This isn't that lengthy of a process, but it is required if you want to go beyond 217. Also, 252 is an older signature, 265 is been out now for a few. Just an idea of how fast these signatures update. Shoot a reply back if you don't know how to upgrade.

Also note that 4.x has been discontinued for signature support (officially) and that you'll move to a license model for signature updates ($$) in the 5.x code. Just be aware you'll need to get another license after you upgrade.

FYI, the latest 5.x code is 5.1(4) with S265.

Run the ciddump and dump to display... After it goes through its process, you should be good to go.

Review Cisco Networking for a $25 gift card