12-17-2012 12:39 AM - edited 03-10-2019 05:51 AM
Hello all,
I would like to know, if the signature version update (e.g. from 665 to 667) could affect tuned signatures.
For an instance, if the severity or fidelity value is changed from default to tuned value prior the update.
Does the update set the default values according to Cisco methodology or let my previously set values?
Thank you for your answer,
BR
Kamil
12-17-2012 07:58 AM
Hi Kamil,
The IPS update should not touch your tuned values if they are set prior to the update.
12-18-2012 08:10 PM
I found something in the older Cisco documentation for IPS IOS 5. Maybe it could be usable for newer systems also:
When new signatures are replacing older signatures, Cisco IOS IPS provides the ip ips inherit-obsolete-tunings command to enable new signatures to obsolete older signatures and inherit the event-action and enabled parameters of the obsolete tuning values, without the need to manually tune the new signatures. This functionality is called signature tuning inheritance. All other parameter changes including the "Retire" parameter is ignored.
After you enter the command, the screen displays a warning message asking you to clarify the intended usage and then asks whether you accept the configuration or not. By default, old signatures are not inherited by new signatures.
SUMMARY STEPS1. enable
2. configure terminal
3. ip ips inherit-obsolete-tunings
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide