IDSMC questions - update sensor to v4, copy single signature
Hi, I am testing update of sensor appliance (ids4235) from v3 to v4. The custom signatures, and the changed parameters (thresholds etc) for regular signatures do not show up in the updated v4 settings in IDSMC.
The procedure I used was:
- add v3 sensor (s62) to IDSMC (the signature settings look good).
- reimage sensor to v4, and upgrade to S62.
- use idsmc to update to v4
The audit report shows that:
- Signature conversion for Sensor sr-vms32 completed, 775 signatures converted 20 signatures were not able to be converted since they were not found in the 4.1(3)S62 signature list.
- The conversion to IDS version 4 for sr-vms32 could not convert the settings for the signature with the id of 20012.
Most of the 20 signatures not converted do appear in the signature list - engine types changed? The filters also look ok in V4.
But signature 1100, 1103, the custom signatures, and the changed parameters were not migrated.
(1) How to update the sensors so that all the valid v3 data will be preserved? Will there be similiar problems if I need to add a preconfigured v4 sensor to idsmc in the future?
(2) I am using vms 2.2, idsmc 1.2 on w2k.
I tried idsmc 1.2.3, hangs quit a bit. Is there a way to backout 1.2.3 to 1.2, without reinstalling?
(3) Is there a way to copy a single signature only from 1 sensor to a number of sensors?
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...