I configured Automatic update from Cisco.com on the IPS-SSM-20 and I have a question about how updates work. Updates are related to the Engine and the Signature only, is that correct ?
In case that a new signature is posted on Cisco.com does the automatic update does the signature update only ?
what about SW Engine in this case is just skipped ...
Correct, only Signature Updates and Engine Updates will be automatically downloaded from cisco.com.
This is because both types of updates can be applied to running sensors without a reboot.
If an Inline sensor is configured for ByPass Auto, then the traffic will continue to flow through the sensor unmonitored while the update is taking place.
Major Updates, Minor Updates, Service Packs, and Patches are NOT automatically updated from cisco.com.
These updates require a reboot for installation andwill cause traffic to stop for a short period when applied. They should be applied during scheduled network down times.
(NOTE: You can set up your own ftp/scp server. Manually download these updates, and palce them on your server. Then configure your sensors to check your own ftp/scp server for these types of updates. Both cisco.com automatic updates, and automatic updates from your own server can be configured on the same sensor.)
Engine updates are only released a few times a year, while signature updates are released several times a month (even several times a week, or even several a day on occasion).
The sensor connects to cisco.com and queries the server for the names of the latest Engine and Signature updates.
It then checks to see if these updates are newer than what is currently on the sensor.
If there is a newer Engine Update (higher E level), then it downloads and installs the new Engine Update.
If the Engine Update on cisco.com is the same E level as what is already on the sensor, then it checks the S level of the latest Signature Update.
If the S level of the newest Signature Update is higher than what is on the sensor, then downloads and installs the new Signature Update.
If the E level and S level on the sensor are the same as the newest Engine Update and Signature Update, then the sensor is up to date. No files are downloaded, and the sensor just waits till the next scheduled auto update time to repeat the process.