Solved! Go to Solution.
Thank you so much for your help.
is the licence only for update the signature or something else? how about with the Anti Virus update ?
Should we buy a license if the license is expired or we are just download a new signature for it.
The AV version you see in the 'show version' of your IPS sensor no longer needs to be updated.
It was part of a coloboration between Cisco and Trend Micro, that no longer exists; you can safely ignore the AV updates.
Please note that Cisco's IPS sensors do not perform DNS resolution for signature updates. The signature auto-uopdate URL must be entered in IP address notation, and not FQDN. You will want:
The double-slash after the IP address is not a typo.
The license key allows for signature updates. If the license expires you will need to acquire a new license (usually tied to your service contract on the IPS in question) in order to continue updating the IPS signatures.
Umm, I tried to access both links..
I could access the page using the link with one slash (https://220.127.116.11/cgi-bin/front.x/ida/locator/locator.pl), but I couldn't access the page using the link with two slashes (https://18.104.22.168//cgi-bin/front.x/ida/locator/locator.pl) with the error message: "The Page you requsted is not available".
So, which on of the the correct one ?
Is the license just needed in automatically-updating the intrusion signature (not including firmware/engine update) ?
How long approximately is the signature update released periodically by Cisco ?
The URL with double slashes should be used. This most probably has something to do with reserved characters in LINUX/Cisco IPS and the double slash is used to represent a single slash only. Since you are testing it in your non-unix browser, you have to put only one slash.
Service Packs and Software upgrades to not require a valid license in order to be installed on the sensor. However signature updates require a valid license to be installed on the sensor, prior to installation.
Thanks for the reply.
Is the link auto-generated ?
If the license only used for updating the signature, and we must update the firmware manually, what is the advantage of buying the license renewal for customer where he could updating his signature manually when he has smartnet coverage (id for downloading the signature from Cisco.com) ?