Live Protect

Feature history for Live Protect

This table provides release and platform support information for the features explained in this module.

These features are available in all the releases subsequent to the one they were introduced in, unless noted otherwise.

Release

Feature name and description

Supported platform

Cisco IOS XE 26.2.1

Live Protect: This feature provides real-time, kernel-level security using eBPF technology through the Tetragon agent embedded in the IOS XE software.

Cisco C9350 Series Smart Switches

Cisco C9550 Series Smart Switches

Cisco C9610 Series Smart Switches

Install Live Protect Shield: 1-step process

This task shows how to use the single install add file activate commit command for installing a Live Protect Shield.

Procedure


Step 1

enable

Example:

Device> enable

Enables privileged EXEC mode.

Enter your password if prompted.

Step 2

install add file flash: filename activate commit

Example:

Device# install add file flash:cisco9k_iosxe.26.02.01.CVE-1900-99999.lps.SPA.bin activate commit

Copies the live protect shield update package from flash to the device, performs a compatibility check for the platform and image versions, activates the package, and makes the package persistent across reloads.

This command extracts the individual components of the .bin file into the subpackages and packages.conf files.

You can also copy the package from a remote location (through FTP, HTTP, HTTPS, or TFTP).

Step 3

show install summary

Example:

Device# show install summary

Displays installed packages information of the software image and live protect shield.

Step 4

show platform software live-protect shield

Example:

Device# show platform software live-protect shield

Displays live protect shield IDs, modes, and the number of hits.

Step 5

configure terminal

Example:

Device# configure terminal

Enters global configuration mode.

Step 6

[no] platform security live-protect shield lpshield-id enforcing

Example:

Device(config)# platform security live-protect shield CVE-2023-20190.01 enforcing

Sets the live protect shield to enforcing mode. By default, monitoring mode is enabled once the live protect shield package is installed.

Step 7

exit

Example:

Device(config)# exit

Exits global configuration mode and returns to privileged EXEC mode.

Step 8

show platform software live-protect shield lpshield-id

Example:

Device# show platform software live-protect shield

Displays live protect shield IDs, modes, and the number of hits.


Install Live Protect Shield: 3-step process

This task shows you the 3-step process for installing a Live Protect Shield.

Procedure


Step 1

enable

Example:

Device> enable

Enables privileged EXEC mode.

Enter your password if prompted.

Step 2

install add file flash: filename

Example:

Device# install add file flash:cisco9k_iosxe.26.02.01.CVE-1900-99999.lps.SPA.bin

Copies the live protect shield update package from flash to the device, performs a compatibility check for the platform and image versions.

This command extracts the individual components of the .bin file into the subpackages and packages.conf files.

You can also copy the package from a remote location (through FTP, HTTP, HTTPS, or TFTP).

Step 3

install activate file flash: filename

Example:

Device# install activate file flash:cisco9k_iosxe.26.02.01.CVE-1900-99999.lps.SPA.bin

Activates the package file that was added and updates the package status details.

Step 4

install commit

Example:

Device# install commit

Commits the activation changes to be persistent across reloads.

The commit can be done after activation while the system is up, or after the first reload. If a package is activated but not committed, it remains active after the first reload, but not after the second reload.

Step 5

show install summary

Example:

Device# show install summary

Displays installed packages information of the software image and live protect shield.

Step 6

show platform software live-protect shield

Example:

Device# show platform software live-protect shield

Displays live protect shield IDs, modes, and the number of hits.

Step 7

configure terminal

Example:

Device# configure terminal

Enters global configuration mode.

Step 8

[no] platform security live-protect shield lpshield-id enforcing

Example:

Device(config)# platform security live-protect shield CVE-2023-20190.01 enforcing

Sets the live protect shield to enforcing mode. By default, monitoring mode is enabled once the live protect shield package is installed.

Step 9

exit

Example:

Device(config)# exit

Exits global configuration mode and returns to privileged EXEC mode.

Step 10

show platform software live-protect shield lpshield-id

Example:

Device# show platform software live-protect shield

Displays live protect shield IDs, modes, and the number of hits.


Verify Live Protect configuration

To verify the Live Protect feature configuration, use these show commands:

Command

Purpose

show install summary

Displays installed packages information, like software image and live protect shield filenames and versions.

show install package {bootflash: | crashinfo: | flash: | webui:} file-name

Displays package details which are added for the shield.

show platform software live-protect shield

Displays live protect shield IDs, modes, and the number of hits.

show platform software live-protect slot switch {switch-number | active | standby}

Displays the switch number or type along with the aggregate live protect hit counters.

This is a sample output from the show install summary command:

Device# show install summary

[ Switch 1 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
            C - Activated & Committed, D - Deactivated & Uncommitted
--------------------------------------------------------------------------------
Type  St   Filename/Version
--------------------------------------------------------------------------------
IMG   C    26.02.01.0.237015
LPS   C    flash:cisco9k_iosxe.26.02.01lpseft3.CVE-1900-99999.lps.SPA.bin

This is a sample output from the show install package flash: command:

Device# sshow install package flash:cisco9k_iosxe.26.02.01.CVE-2026-10000-v01.lps.SSA.bin

Name: cisco9k_iosxe.26.02.01.CVE-2026-10000-v01.lps.SSA.bin

Version: 27.01.01.0.251074.1786667099..IOSXE

Platform: CISCO9K

Package Type: LPS

Defect ID: CSCaa15401

Package State: Activated & Committed

Supersedes List: {}

LPS Fixes List: CVE-2026-10000

LPS Build ID: 154

LPS Type: non-reload

LPS Compatible with Version: 26.02.01

LPS Impact: Dummy WebUI Vulnerability Shield. User will not be able to edit a file in nginx

LPS Supported Family: cisco9k

This is a sample output from the show platform software live-protect shield command:

Device# show platform software live-protect shield

Aggregate Live Protect Hit Counters
LP Shield ID          Mode          Enforcing Hits   Monitoring Hits  Total Hits
---------------------------------------------------------------------------------
cve-2026-10000-v01    Enforcing     21               27               48        
cve-2026-10011-v02    Monitoring    0                48               48        

This is a sample output from the show platform software live-protect slot switch 4 r0 shield command:

Device# show platform software live-protect slot switch 4 r0 shield

Aggregate Live Protect Hit Counters
Member Switch  LP Shield ID          Mode          Enforcing Hits   Monitoring Hits   Total Hits
--------------------------------------------------------------------------------------------------
4              cve-2026-10000-v01    Enforcing     17               0                 17        
4              cve-2026-10011-v02    Monitoring    0                17                17        
4              cve-2026-10111-v03    Enforcing     17               0                 17        
4              cve-2026-11111-v04    Monitoring    0                17                17        
4              cve-2026-11110-v05    Enforcing     17               0                 17