I'd like to apply a consistent signature policy across several routers using IOS IPS and managed by a Cisco Security Manager. I've created the new Policy, and the signatures are setup in a default manner. I'd like to perform the equivalent of the 'category all' and 'retired true' commands and then begin building my policy but I can't figure out how.
Is there a way to retire all of the signatures and then un-retire the categories/signatures that are relevant to my environment? Besides editing them individually, of course.
I only manage IDS devices through CSM so this may not be accurate for you but you can highlight multiple lines and then right click to change actions (note that it matters on which field you right click).