cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1704
Views
0
Helpful
2
Replies

SourceFire IPS updates

Colin Higgins
Level 2
Level 2

We are in the process of putting in new firewalls with SFP IPS modules in them that will be managed by a SourceFire security center appliance (a 1500 series)

 

I know with the old IPS systems, the modules would get their signature updates directly. Will they now get their signature and software updates from the management server? (this would make things a lot easier)

1 Accepted Solution

Accepted Solutions

pazzi
Cisco Employee
Cisco Employee

Hello Colin

 

Yes, your Firesight management center gets all the rules updates and the Intrusion policies get updated and redeployed to your sensors.

 

Hth

Paul

View solution in original post

2 Replies 2

pazzi
Cisco Employee
Cisco Employee

Hello Colin

 

Yes, your Firesight management center gets all the rules updates and the Intrusion policies get updated and redeployed to your sensors.

 

Hth

Paul

That sounds good

 

The reason I ask, is that some of the firewalls are edge devices providing outbound Internet access. I don't want to hairpin traffic off an internal router so that the IPS module can go fetch updates from Cisco.

 

I would much rather keep that management IP for the sensor isolated and have the server push updates to it.

Review Cisco Networking products for a $25 gift card