Cisco Cisco IPS 4255 Sensor
4
Release Notes for Cisco Intrusion Prevention System 6.0(6)E4
OL-21669-01
ROMMON and TFTP
ROMMON and TFTP
ROMMON uses TFTP to download an image and launch it. TFTP does not address network issues such
as latency or error recovery. It does implement a limited packet integrity check so that packets arriving
in sequence with the correct integrity value have an extremely low probability of error. But TFTP does
not offer pipelining so the total transfer time is equal to the number of packets to be transferred times
the network average RTT. Because of this limitation, we recommend that the TFTP server be located on
the same LAN segment as the sensor. Any network with an RTT less than a 100 milliseconds should
provide reliable delivery of the image. Be aware that some TFTP servers limit the maximum file size that
can be transferred to ~32 MB.
as latency or error recovery. It does implement a limited packet integrity check so that packets arriving
in sequence with the correct integrity value have an extremely low probability of error. But TFTP does
not offer pipelining so the total transfer time is equal to the number of packets to be transferred times
the network average RTT. Because of this limitation, we recommend that the TFTP server be located on
the same LAN segment as the sensor. Any network with an RTT less than a 100 milliseconds should
provide reliable delivery of the image. Be aware that some TFTP servers limit the maximum file size that
can be transferred to ~32 MB.
For More Information
•
For the procedure for downloading IPS software updates from Cisco.com, see
.
•
For the procedure for configuring automatic updates, for the CLI refer to
, and for IDM refer to
IPS Management and Event Viewers
Use the following tools for configuring IPS 6.0(6)E4 sensors:
•
IDM 6.0(2)
•
IPS CLI 6.0
•
ASDM 5.2
Note
We recommend that ASDM users upgrade to ASDM 6.3 or later. The Java VM upper
memory limit of ASDM 6.3 has been increased. Older versions of ASDM may not have
enough available memory for IDM 6.0(2) to function properly.
memory limit of ASDM 6.3 has been increased. Older versions of ASDM may not have
enough available memory for IDM 6.0(2) to function properly.
•
CSM 3.2.2 and later
Use the following tools for monitoring 6.0(6)E4 sensors:
•
MARS 4.2 and 4.3(1)
•
IEV 5.2
•
CSM 4.0
Note
Viewers that are already configured to monitor the 5.x sensors may need to be configured to
accept a new SSL certificate for the 6.0(6)E4 sensors.
accept a new SSL certificate for the 6.0(6)E4 sensors.
For More Information
For more information about IDM and the Java VM memory requirements, see
.