cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
554
Views
0
Helpful
1
Replies

sig0

ohassairi
Level 5
Level 5

hello

i am using the IPS module (ASA-SSM-10) in the cisco firewall ASA5510 with the default signature :sig0

i noted that some DDoS and Virus/worms/trojans are not activated by default in sig0

i wonder why? i think they are high risk issues. and is it a best practice to enable them?

thanks

1 Reply 1

turnera
Level 1
Level 1

The signatures are basically sent to the customer in a default or base state. If you feel that you need to enable those signatures, then by all means, go ahead. That is why they are there. It is not a 'one size fits all' out of the box database configuration.

You, as a user, have the choice to enable them or disable them. It depends on your environment as to how you wish to implement. Tweak the signatures where you feel they need tweaking.

Review Cisco Networking for a $25 gift card