cisco ips link update signature automatically ?

Answered Question
Farrukh Haroon Thu, 07/08/2010 - 06:34
User Badges:
  • Red, 2250 points or more

The AV version you see in the 'show version' of your IPS sensor no longer needs to be updated.


It was part of a coloboration between Cisco and Trend Micro, that no longer exists; you can safely ignore the AV updates.


Regards


Farrukh

Scott Fringer Thu, 07/08/2010 - 07:16
User Badges:
  • Cisco Employee,

Please note that Cisco's IPS sensors do not perform DNS resolution for signature updates.  The signature auto-uopdate URL must be entered in IP address notation, and not FQDN.  You will want:


https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.pl


The double-slash after the IP address is not a typo.


The license key allows for signature updates.  If the license expires you will need to acquire a new license (usually tied to your service contract on the IPS in question) in order to continue updating the IPS signatures.


Scott

Farrukh Haroon Thu, 07/08/2010 - 07:22
User Badges:
  • Red, 2250 points or more

Thanks for the correction Scott.


I totally forgot abou that, as I got that URL from MARS.


Regards


Farrukh

DanielQan Thu, 07/08/2010 - 19:46
User Badges:

Umm, I tried to access both links..

I could access the page using the link with one slash (https://198.133.219.25/cgi-bin/front.x/ida/locator/locator.pl), but I couldn't access the page using the link with two slashes (https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.pl) with the error message: "The Page you requsted is not available".

So, which on of the the correct one ?


Is the license just needed in automatically-updating the intrusion signature (not including firmware/engine update) ?


How long approximately is the signature update released periodically by Cisco ?


Regards,

Daniel

Farrukh Haroon Thu, 07/08/2010 - 20:16
User Badges:
  • Red, 2250 points or more

Hello Daniel


The URL with double slashes should be used. This most probably has something to do with reserved characters in LINUX/Cisco IPS and the double slash is used to represent a single slash only. Since you are testing it in your non-unix browser, you have to put only one slash.


Service Packs and Software upgrades to not require a valid license in order to be installed on the sensor. However signature updates require a valid license to be installed on the sensor, prior to installation.


Regards


Farrukh

DanielQan Thu, 07/08/2010 - 20:39
User Badges:

Hello Farrukh,


Thanks for the reply.


Is the link auto-generated ?


If the license only used for updating the signature, and we must update the firmware manually, what is the advantage of buying the license renewal for customer where he could updating his signature manually when he has smartnet coverage (id for downloading the signature from Cisco.com) ?


Regards,

Daniel

Farrukh Haroon Thu, 07/08/2010 - 20:48
User Badges:
  • Red, 2250 points or more

The link is static and not auto-generated (If I understood your question correctly).


There is no smartnet for IPS boxes. You have to purchase something called 'Cisco Services for IPS which is basically Smartnet + Signature Updates bundled into a single support offering.


The license cost is associated with the signature updates; because keeping up with the emerging threats and creating the associated signatures requires a lot of effort from Cisco. The license has nothing to do with manual or auto updating.  This is solely as per the security/business requirement of the end-user. The Cisco IPS does however provide both options (manual or auto), one may choose whichever method is more suitable. Irrespective of the method you choose, you would need to have a valid license installed to download and install sig. updates.


Regards


Farrukh

Farrukh Haroon Sat, 01/21/2012 - 00:25
User Badges:
  • Red, 2250 points or more

Please provide more details about your scenario:


> Did the problem appear now or they never worked?

> Is Internet connectivity functional?

> Is DNS functional on the box?

> What is the URL you are using?

> Do you have a proxy-server based access?

etc.


Regards


Farrukh

Diego Maciel Gomes Wed, 07/25/2012 - 05:05
User Badges:

Hello All


I updated my IPS to last version and last signature. It was 5 days ago.


Well, I configured Autoupdate with the URL that was in the device, by default. I put my cisco login and schedule.


I check the autoupdate info and it shows Last Directory and Next Attempt.


Last Download and Last Install shows N/A.


URL below:


https://72.163.4.161//cgi-bin/front.x/ida/locator/locator.pl


why the update doesnt work? How can I see a log for it?


Thanks anyway


Diego

Actions

This Discussion