cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
492
Views
0
Helpful
10
Replies

CTR upgrade to VMS - when?

david.d
Level 1
Level 1

Early December there was indication that the temporary application "Cisco Threat Response" was to be replaced with a lite/free (no word on what Cisco is to call it) verson of VMS to run on Windows only. Then it was to be late December and now by mid February.

Has anyone heard anything about a release date?

1 Accepted Solution

Accepted Solutions

scoclayton
Level 7
Level 7

Hi,

I think the new name is VMS Basic. It has a 5 device restriction and is currently available via the Product Upgrade Tool on CCO (http://tools.cisco.com/gct/Upgrade/jsp/index.jsp) to anyone that has a current Smartnet contract on their 42XX sensors. All new sensors should come bundled with this application already. Hope this helps.

Scott

View solution in original post

10 Replies 10

scoclayton
Level 7
Level 7

Hi,

I think the new name is VMS Basic. It has a 5 device restriction and is currently available via the Product Upgrade Tool on CCO (http://tools.cisco.com/gct/Upgrade/jsp/index.jsp) to anyone that has a current Smartnet contract on their 42XX sensors. All new sensors should come bundled with this application already. Hope this helps.

Scott

Thanks for the reply Scott. Been waiting for this since November.

marcabal
Cisco Employee
Cisco Employee

The Basic version of VMS is now available.

It contains IDS MC (IDS Management Center) for configuring the sensors, and SecMon (Security Monitoring Center) for viewing alarms.

The part number is: CWVMS-2.2-B-SR-K9

For IDS customers with SmartNET service contracts on their sensors they can go through the PUT (Product Upgrade Tool) on CCO:

http://tools.cisco.com/gct/Upgrade/jsp/index.jsp

The VMS Basic is available at no extra charge for IDS customers with SmartNET contracts on their sensors.

VMS Basic has a limited device license (I think it will limit you to either 3 or 5 sensors).

For more than 5 sensors, user will still need to purchase the standard VMS licenses.

The VMS Basic is only available on CD because of the size of the files, and will not be available as download from CCO.

The VMS Basic CD can already be ordered through PUT, but an official announcement has not been made that I know of.

The CD will also be included in the box with all new sensor purchases, but this is requiring a few changes in manufacturing.

Once those changes are made to include the CD in new sensor orders then I think the official announcement will go out. But you can go ahead and order the VMS Basic CD through PUT today.

Now the next question is about CTR and VMS. Currently CTR is a standalone application available at no extra cost. It will not work on the same machine where VMS has been installed.

There are no changes with CTR with the release of VMS Basic. VMS Basic is the same VMS version previously released with the exception of the limited device license at no extra cost to IDS SmartNET customers. There was some confusion that the first release of VMS Basic would contain CTR integration, but there is not integration between the 2 products with this initial VMS Basic release.

So you will still need to choose between CTR and VMS for monitoring your sensors.

As for the future of CTR and VMS in the next versions, and what the pricing structures may be; you will need to wait for formal announcements on the next versions of those products.

Is there a work around for running VMS and CTR, or either of those + ACS on the same box?

All these windows management boxes are proliferating, and they're the only windows servers at our company - it's embarassing.

There's always VMware I suppose.

That's an interesting question. My first thoughts were that VMS would replace CTR in functionality. That CTR was just a temporary stopgap. Don't know for sure.

My perception of VMS was of a UNIX platform (Solaris) ported for NT so I expected an application to run on my Solaris or Linux systems.

I'm not familiar with the history of these applications nor the technical/marketing reasons but it does seem short sighted to release only on NT. Of course if these are beta applications then it may be premature to voice concerns. Our local Cisco contacts are not aware of dates or platforms for these applications but I would expect Cisco to pony up and give us some options.

The purchase copy of VMS is available on both Solaris and Windows.

It is just the no additional cost VMS Basic that is only for Windows (at least that is what I've heard, I have not seen the formal documentation, so it may actually also be available for Solaris).

So if you want the Unix support then purchase the license to run VMS on Solaris.

As for VMS replacing CTR functionality. I can't really comment on that at the moment.

VMS Basic is still the same version as what has been for sale for the past few months with just a new no additional cost license.

CTR is still the same CTR available at no extra cost for the initial offering period as a trial version on Windows only.

As for the future of VMS and CTR this information can not be discussed on an open public forum before official product announcements. You would need to contact your Cisco Sales Representative and have a confidential conversation on the product roadmaps.

Considering that VMS was available years BEFORE CTR, it is not possible for VMS to replace CTR. If anything, individuals should be wondering if CTR will replace VMS. There seems to be alot of confusion between VMS and CTR.

CTR's only use is for alert viewing and management from IDS sensors. Period.

VMS is a security management suite for most Cisco security products. It also has an alert management utility (Security Monitor) that handles IDS alarms, Pix IDS messages, IOS IDS messages, CSA, etc. It doesn't have the "intelligence" that CTR does for investigating and correlating alarms.

Additionally, VMS also provides for management of devices such as firewalls, IDSs, VPN IOS. It also handles software and signature updates.

VMS Basic is not entirely the same as the full version. VMS Basic is a "free", Windows only version with restricted licensing and functionality. Functionality is restricted in that it does not include RME or Security Performance Monitor.

In the future, the functionality of CTR will probably be rolled into the VMS suite as they overlap.

As for running VMS, CTR, and ACS together on the same box using VMWare, VirtualPC, etc. I don't recommend it. VMS and CTR are Java based apps. As you probably know, Java is fat and slow. Unless you've got an incredibly beefy server, VMS and CTR would crawl very slowly in a virtual machine. However, if your ACS authentication needs are pretty light, you could probably get away with running it in a virtual machine. This still leaves you with two machines though to run CTR and VMS. Better than 3..... ;)

This is exactly what I've ended up doing; 1 dual Xeon box running VMS + ACS & RSA ACE server in a VMware instance, 1 dual PIII box running CTR.

My limitation though is RAM rather than CPU or I/O, if I were prepared to drop the $$$ for VMware server edition (Workstation is $300 but limited to 1GB RAM, Server is $3000 unlimited RAM) I think I could get CTR running fine.

Boxes are getting very powerful now, for $7K I can get a box with dual 1MB cache Xeons (cache size make Java run much faster), 6GB RAM, RAID etc, in a 1U form factor, each U of space costs me $2K PA, so this is more cost effective than running 3 boxes.

In the long run Cisco's software teams need to get their act together on Java and Tomcat versions, and get this stuff co-habiting, and while they're at it I wish CiscoWorks didn't force you to run an old version of Java on the client, I'm having to use VMware for that too, as I have other apps that need the latest version.

This reply does help. VMS was presented to me by Cisco as a replacement for CTR so they may still be doing homework as to how to package services for IDS. That discussion was last November so things could have evolved quite a bit since then.

Thanks for the explanation.

david.d
Level 1
Level 1

fwiw, I received my copy of VMS Feb 10.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: