Hello all,
I would like to know, if the signature version update (e.g. from 665 to 667) could affect tuned signatures.
For an instance, if the severity or fidelity value is changed from default to tuned value prior the update.
Does the update set the default values according to Cisco methodology or let my previously set values?
Thank you for your answer,
BR
Kamil
Hi Kamil,
The IPS update should not touch your tuned values if they are set prior to the update.
I found something in the older Cisco documentation for IPS IOS 5. Maybe it could be usable for newer systems also:
When new signatures are replacing older signatures, Cisco IOS IPS provides the ip ips inherit-obsolete-tunings command to enable new signatures to obsolete older signatures and inherit the event-action and enabled parameters of the obsolete tuning values, without the need to manually tune the new signatures. This functionality is called signature tuning inheritance. All other parameter changes including the "Retire" parameter is ignored.
After you enter the command, the screen displays a warning message asking you to clarify the intended usage and then asks whether you accept the configuration or not. By default, old signatures are not inherited by new signatures.
SUMMARY STEPS1. enable
2. configure terminal
3. ip ips inherit-obsolete-tunings