![]() |
||||||||||||||||||||
Cisco Services for IPS on IOS
![]() |
||||||||||||||||||||
Contents
Cisco Services for IPS on IOSLast Updated: August 15, 2012
The Cisco Services for IPS on IOS feature enforces the presence of a valid Intrusion Prevention System (IPS) subscription license before loading signatures released beyond a certain date when the IOS IPS is enabled. A Cisco Services for IPS contract must be purchased or renewed in order to be able to load new signatures; otherwise, the feature will not detect or stop the new attacks making the feature useless. This feature adds license checking to the signature packages that are distributed by Cisco Systems, Inc. and loaded on IOS Integrated Services Routers (ISR). IOS IPS is enabled on ISRs to detect and act on signatures. Signature packages are created by the signature team and distributed on www.cisco.com. As the signature package is loaded on the ISR, a check is performed to see if there is a valid subscription license for loading IPS signatures. The date of the signature releases contained in the package are checked against the expiration date of the subscription license. Any signatures that are released before the expiration date are loaded and those released after the expiration date are not loaded.
Finding Feature InformationYour software release may not support all the features documented in this module. For the latest caveats and feature information, see Bug Search Tool and the release notes for your platform and software release. To find information about the features documented in this module, and to see a list of the releases in which each feature is supported, see the feature information table at the end of this module. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. Prerequisites for Cisco Services for IPS on IOS
Information About Cisco Services for IPS on IOS
Cisco Services for IPS Service ContractCisco Services for IPS is a service contract that includes smartNet services along with an IPS signature update subscription, that allows generation of an IPS subscription license file that is unique for the router the service contract has been sold for. For further information on Cisco Services for IPS, see the Cisco Services for IPS document. Cisco IOS IPS Subscription License DetailsA Cisco IOS IPS Subscription License is a license to enable a router to load signatures released after a certain date. It is not a license to either turn on the IPS feature or to download IPS signature packages from CCO. Cisco CA will require a Cisco Services for IPS contract purchase to generate a license file based on the router Product ID (PID) and Serial Number (SN). A 60-day trial license can be generated once for each PID and SN combination (also called UDI - Universal Device Identifier). Cisco IOS IPS Signature Package The latest Cisco IOS IPS signature package can be accessed from Cisco.com using the following URL:
http://www.cisco.com/cisco/software/release.html?mdfid=281442967&release=S636&relind=AVAILABLE&flowid=4836&softwareid=280775022&rellifecycle=&reltype=latest
IPS Subscription License VerificationCisco IOS Software Licensing (CSL) provides a framework for verifying licenses on a router running Cisco IOS software. IOS IPS needs to query CSL to determine if the license file is valid and that the router has permission to load the latest signature update. If the license is valid, the new signatures may be loaded. If the license is not valid or unavailable, the signature will not be loaded. If the license is expired, only those signature updates that were produced before the license expiration date may be loaded. How to Work with Cisco Services for IPS on IOSDisplaying the Status of an IPS LicensePerform this task to display the status of a license. The show ip ips license command displays IPS license information. This information includes the license expiration date and the version date of the existing loaded signatures, as well as the highest version date of last signature package loaded. If the license is still valid, the existing loaded signature version is the same as the last signature package. DETAILED STEPS Configuration Examples for Cisco Services for IPS on IOS
Displaying Valid License Details: ExampleThe following task displays the details of a valid license: Router# show ip ips license IPS License Status Valid Expiration Date: 2009-12-31 Signatures Loaded: 2009-06-25 S375 Signature Package: 2009-06-25 S375 Displaying the Details of an Expired License: ExampleThe following example displays the details of an expired license: Router# show ip ips license IPS License Status Expired Expiration Date: 2009-12-31 Signatures Loaded: 2009-12-25 S393 Signature Package: 2010-03-10 S402 Additional ReferencesRelated DocumentsMIBsTechnical Assistance
Feature Information for Cisco Services for IPS on IOSThe following table provides release information about the feature or features described in this module. This table lists only the software release that introduced support for a given feature in a given software release train. Unless noted otherwise, subsequent releases of that software release train also support that feature. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. © 2012 Cisco Systems, Inc. All rights reserved.
|
||||||||||||||||||||
|
|