cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1138
Views
0
Helpful
2
Replies

Signature update impact on tuned signatures

hepterida
Level 1
Level 1

Hello all,

I would like to know, if the signature version update (e.g. from 665 to 667) could affect tuned signatures.

For an instance, if the severity or fidelity value is changed from default to tuned value prior the update.

Does the update set the default values according to Cisco methodology or let my previously set values?

Thank you for your answer,

BR

Kamil     

2 Replies 2

_____Adam
Level 1
Level 1

Hi Kamil,

The IPS update should not touch your tuned values if they are set prior to the update.

I found something in the older Cisco documentation for IPS IOS 5. Maybe it could be usable for newer systems also:

(http://www.cisco.com/en/US/docs/ios-xml/ios/sec_data_ios_ips/configuration/12-4t/sec-ips5-sig-fs-ue.html)

Enabling Signature Tunings Inheritance

When new signatures are replacing older signatures, Cisco IOS IPS provides the ip ips inherit-obsolete-tunings command to enable new signatures to obsolete older signatures and inherit the event-action and enabled parameters of the obsolete tuning values, without the need to manually tune the new signatures. This functionality is called signature tuning inheritance. All other parameter changes including the "Retire" parameter is ignored.

After you enter the command, the screen displays a warning message asking you to clarify the intended usage and then asks whether you accept the configuration or not. By default, old signatures are not inherited by new signatures.

SUMMARY STEPS

1.    enable

2.    configure terminal

3.    ip ips inherit-obsolete-tunings


DETAILED STEPS
Command or ActionPurpose

Step 1

enable


Example:

Router> enable

Enables privileged EXEC mode.

  • Enter your password if prompted.

Step 2

configure terminal


Example:

Router# configure terminal

Enters global configuration mode.

Step 3

ip ips inherit-obsolete-tunings

Example:

Router(config)#ip ips inherit-obsolete-tunings

Enables the inheritance of the tunings of the enabled and event-action parameters from obsolete signatures to new signatures in an IPS,

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: