Cisco Cisco IPS 4255 Sensor Notas de publicación

Descargar
Página de 42
   
4
Release Notes for Cisco Intrusion Prevention System 6.0(6)E3
OL-20113-01
  ROMMON and TFTP
Serv-U 5.0 (Windows 2000)
MS IIS 5.0 (Windows 2000)
The following HTTP/HTTPS servers are supported for IPS software updates:
CMS - Apache Server (Tomcat)
CMS - Apache Server (JRun) 
Note
The 6.0(x) sensor cannot download software updates from Cisco.com. You must download the software 
updates from Cisco.com to your FTP server, and then configure the sensor to download them from your 
FTP server. In versions 6.1(1) and higher, automatic updates from Cisco.com are available.
ROMMON and TFTP
ROMMON uses TFTP to download an image and launch it. TFTP does not address network issues such 
as latency or error recovery. It does implement a limited packet integrity check so that packets arriving 
in sequence with the correct integrity value have an extremely low probability of error. But TFTP does 
not offer pipelining so the total transfer time is equal to the number of packets to be transferred times 
the network average RTT. Because of this limitation, we recommend that the TFTP server be located on 
the same LAN segment as the sensor. Any network with an RTT less than a 100 milliseconds should 
provide reliable delivery of the image. Be aware that some TFTP servers limit the maximum file size that 
can be transferred to ~32 MB.
For More Information
For the procedure for downloading IPS software updates from Cisco.com, see 
For the procedure for configuring automatic updates, refer to 
IPS Management and Event Viewers
Use the following tools for configuring IPS 6.0(6)E3 sensors:
IDM 6.0
IPS CLI 6.0
ASDM 5.2
CSM 3.2
Use the following tools for monitoring 6.0(6)E3 sensors:
MARS 4.2 and 4.3(1)
IEV 5.2
CSM 4.0
Note
Viewers that are already configured to monitor the 5.x sensors may need to be configured to 
accept a new SSL certificate for the 6.0(6)E3 sensors.