Cisco Cisco IPS 4345 Sensor
7
Release Notes for Cisco Intrusion Prevention System 7.1(3)E4
OL-25881-01
The Sensor and Jumbo Packet Frame Size
lists the Yellow Threshold and the Red Threshold health values.
For More Information
For the procedure for configuring sensor health metrics, for the IDM refer to
,
for the IME refer to
, and for the CLI refer to
.
The Sensor and Jumbo Packet Frame Size
For IPS standalone appliances with 1 G and 10 G fixed or add-on interfaces, the maximum jumbo frame
size is 9216 bytes. For integrated IPS sensors, such as the ASA 5500-X and ASA 5585-X series, refer to
the following URL for information:
size is 9216 bytes. For integrated IPS sensors, such as the ASA 5500-X and ASA 5585-X series, refer to
the following URL for information:
http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_start.html#wp1328
86
86
9
Note
A jumbo frame is an Ethernet packet that is larger than the standard maximum of 1518 bytes (including
Layer 2 header and FCS).
Layer 2 header and FCS).
The ASA IPS Modules and Jumbo Packets
The jumbo packet count in the show interface command output from the lines
Total Jumbo Packets
Received
and
Total Jumbo Packets Transmitted
for ASA IPS modules may be larger than expected
due to some packets that were almost jumbo size on the wire being counted as jumbo size by the IPS.
This miscount is a result of header bytes added to the packet by the ASA before the packet is transmitted
to the IPS. For IPv4, 58 bytes of header data are added. For IPv6, 78 bytes of header data are added. The
ASA removes the added IPS header before the packet leaves the ASA.
This miscount is a result of header bytes added to the packet by the ASA before the packet is transmitted
to the IPS. For IPv4, 58 bytes of header data are added. For IPv6, 78 bytes of header data are added. The
ASA removes the added IPS header before the packet leaves the ASA.
Obtaining Software
You can find major and minor updates, service packs, signature and signature engine updates, system
and recovery files, firmware upgrades, and Readmes on the Download Software site on Cisco.com.
Signature updates are posted to Cisco.com approximately every week, more often if needed. Service
packs are posted to Cisco.com in a release train format, a new release every three months. Major and
minor updates are also posted periodically. Check Cisco.com regularly for the latest IPS software.
and recovery files, firmware upgrades, and Readmes on the Download Software site on Cisco.com.
Signature updates are posted to Cisco.com approximately every week, more often if needed. Service
packs are posted to Cisco.com in a release train format, a new release every three months. Major and
minor updates are also posted periodically. Check Cisco.com regularly for the latest IPS software.
Table 1
ASA 5500-X IPS SSP Memory Usage Values
Platform
Yellow
Red
Memory Used
ASA 5512-X IPS SSP
85%
91%
28%
ASA 5515-X IPS SSP
88%
92%
14%
ASA 5525-X IPS SSP
88%
92%
14%
ASA 5545-X IPS SSP
93%
96%
13%
ASA 5555-X IPS SSP
95%
98%
17%