Saturday, December 26, 2009

IOS IPS

In order to setup IPS on IOS follow instructions here. My tftp server is at the address 192.10.1.200 and dynamips router has interface 192.10.1.6. The first step is to transfer signature files from tftp server to router.

clip_image002
clip_image004
clip_image006
clip_image008
The signature files are stored in the router flash.
Rack1R6#dir
Directory of flash:/
1 -rw- 7697112 Mar 1 2002 03:03:17 +00:00 IOS-S313-CLI.pkg
16777212 bytes total (9080036 bytes free)
Now setp public key and load signatures .
clip_image010
clip_image012
Rack1R6#show ip ips signature count | i Total
Signature Micro-Engine: multi-string: Total Signatures 8
Signature Micro-Engine: service-http: Total Signatures 622
Signature Micro-Engine: string-tcp: Total Signatures 961
Signature Micro-Engine: string-udp: Total Signatures 75
Signature Micro-Engine: state: Total Signatures 28
Signature Micro-Engine: atomic-ip: Total Signatures 275
Signature Micro-Engine: string-icmp: Total Signatures 3
Signature Micro-Engine: service-ftp: Total Signatures 3
Signature Micro-Engine: service-rpc: Total Signatures 75
Signature Micro-Engine: service-dns: Total Signatures 38
Signature Micro-Engine: normalizer: Total Signatures 9
Signature Micro-Engine: service-smb-advanced: Total Signatures 35
Signature Micro-Engine: service-msrpc: Total Signatures 26
Total Signatures: 2158
Total Enabled Signatures: 930
Total Retired Signatures: 2158
Total Compiled Signatures: 0
Total Obsoleted Signatures: 11
Rack1R6#

No comments: