05-11-2008 05:15 AM - edited 03-10-2019 04:06 AM
Hi,
I am using the SDM and noticed my home 877 can use IPS. Can anyone offer some advise on how to set up IPS on this router, I just want to get something basic running then I can learn from that.
I have 2 interfaces, the dialer 1 (outside) and VLAN1 (inside), should IPS be on both or just the outside?
05-14-2008 09:46 PM
05-14-2008 11:59 PM
Thanks, so I don't have to pay for the IPS signatures etc, I have an accoutn to download from Cisco?
05-15-2008 12:08 PM
No.
05-15-2008 01:20 PM
You don't have to pay for the router based IOS IPS signatures yet. But next year there will be a license requirement in order to even run the IPS feature (not just to upgrade signatures). Fortunately Cisco has a FREE Cisco License Manager to help you with all your new licensing requirements.
05-16-2008 12:56 AM
Hi,
This really helped, but I have a few questions.
I followed the document, but how do I know it's all working? :) I'm very new to IPS.
I have 2 interfaces:
dialer1 - outside interface
vlan1 - inside
I applied the IPS to the inbound side of dialer 1 is this right?
Also page 13 has a screenshot of all the signatures, inmy SDM it's all blank.
877# sh ip ips con
IPS Signature File Configuration Status
Configured Config Locations: flash:/IPS/
Last signature default load time: 09:28:28 BST May 16 2008
Last signature delta load time: -none-
Last event action (SEAP) load time: -none-
General SEAP Config:
Global Deny Timeout: 3600 seconds
Global Overrides Status: Enabled
Global Filters Status: Enabled
IPS Auto Update is not currently configured
IPS Syslog and SDEE Notification Status
Event notification through syslog is enabled
Event notification through SDEE is enabled
IPS Signature Status
Total Active Signatures: 377
Total Inactive Signatures: 1887
IPS Packet Scanning and Interface Status
IPS Rule Configuration
IPS name sdm_ips_rule
IPS fail closed is disabled
IPS deny-action ips-interface is false
Fastpath ips is enabled
Quick run mode is enabled
Interface Configuration
Interface Dialer1
Inbound IPS rule is sdm_ips_rule
Outgoing IPS rule is not set
IPS Category CLI Configuration:
Category all:
Retire: True
Category ios_ips basic:
Retire: False
877# sh ip ips signature
Cisco SDF release version S333.0
Trend SDF release version V0.0
Just some little pointers would be so much help
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: