Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Dangerous to enable IDS sigs on PIX??

I have a PIX515E running 6.3 with 2 T1's behind it and about 15 3des IPSEC peers. I have heard that turning on all the IDS policies (I will only use informational) for informational alerts on both the inside and outside interfaces can significantly tax the CPU. Will it slow down to the point of affecting network performance? I only have 2 T1s but still when I turn it on I see the CPU jump up higher than normal, usually it is only at 5 percent or lower without IDS turned on... please advise of your experience enabling PIX IDS sigs is dangerous to performance of the firewall.

ryan

1 REPLY
Bronze

Re: Dangerous to enable IDS sigs on PIX??

I could not find any Bugs related to high CPU utilization with the IDS enabled on the PIX. PIX supports only a subset of IDS, 53 common attacks to be more specific. I guess, this tweaking was done keeping in mind the impact on CPU utilization. Guess, you should do fine enabling IDS on the PIX

88
Views
0
Helpful
1
Replies
CreatePlease login to create content