08-24-2011 09:40 AM - edited 03-10-2019 05:27 AM
Hello,
I have successfully downloaded the latest IOS IPS Signature Data File-S573 and installed it on a 2811 cisco router.
I have RETIRED all the signatures in the “all” category.
How do i know which are the recommened signatures to UNRETIRE + ENABLE from the selected signature categories?
regards,
Kevin
Solved! Go to Solution.
08-25-2011 04:22 AM
Kevin,
Cisco recommands to start from ios_basic for platforms with 128 Mb DRAM and with ios_advanced for platforms with 256 Mb DRAM and then start unretiring signatures until (CPU not Buffer) memory drops below 10-20%.
A good read is:
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps7264/ps6634/IOS_IPS_Best_Practices.pdf
Please note that the higher the number of signatures the longer is the boot time of the router.
Unretiring ios_advanced and attacs on a ISG G2 1921 with 256 Mb of DRAM brought my boot time from under two minutes to over 6 minutes (this is the compile time, since signatures are compiled when router boots) and I wnt from 80% memory free to 12% memory free.
I compromised by retiring all and unretiring ios_advanced.
Hope it helps
Fabio
(if this answer is useful to you pls rate it)
08-24-2011 09:54 PM
Kevin,
That doesnt sound right, you cant have all the signatures retired by default. Have you tried downloading the pkg and installing it again?
Thx,
Raga
08-25-2011 01:23 AM
Raga,
The signatures werent all retired by default. Over 500 of them were enabled but i retired these. This is recommened best practise from cisco and then you unretire and enable the signatures you want on the router.
I am looking for advice on which signatures are the best ones to enable from the latest download.
regards,
Kevin
08-25-2011 04:22 AM
Kevin,
Cisco recommands to start from ios_basic for platforms with 128 Mb DRAM and with ios_advanced for platforms with 256 Mb DRAM and then start unretiring signatures until (CPU not Buffer) memory drops below 10-20%.
A good read is:
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps7264/ps6634/IOS_IPS_Best_Practices.pdf
Please note that the higher the number of signatures the longer is the boot time of the router.
Unretiring ios_advanced and attacs on a ISG G2 1921 with 256 Mb of DRAM brought my boot time from under two minutes to over 6 minutes (this is the compile time, since signatures are compiled when router boots) and I wnt from 80% memory free to 12% memory free.
I compromised by retiring all and unretiring ios_advanced.
Hope it helps
Fabio
(if this answer is useful to you pls rate it)
08-26-2011 01:24 AM
Fabio,
Your advice is correct. I have just enabled the basic signatures (This loaded 500+ signatures from the latest .pkg file). I can add on any extra ones if needed as i go along.
thanks
Kevin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide