Cisco Cisco IPS 4255 Sensor 릴리즈 노트

다운로드
페이지 38
   
4
Release Notes for Cisco Intrusion Prevention System 6.0(4)E2
OL-20146-01
  Cisco Security Intelligence Operations
ASDM 5.2
CSM 3.1
Use the following tools for monitoring 6.0(4)E2 sensors:
MARS 4.2 and 4.3(1)
IEV 5.2
CSM 4.0
Note
Viewers that are already configured to monitor the 5.x sensors may need to be configured to 
accept a new SSL certificate for the 6.0(4)E2 sensors.
Cisco Security Intelligence Operations
The Cisco Security Intelligence Operations site on Cisco.com provides intelligence reports about current 
vulnerabilities and security threats. It also has reports on other security topics that help you protect your 
network and deploy your security systems to reduce organizational risk.
You should be aware of the most recent security threats so that you can most effectively secure and 
manage your network. Cisco Security Intelligence Operations contains the top ten intelligence reports 
listed by date, severity, urgency, and whether there is a new signature available to deal with the threat.
Cisco Security Intelligence Operations contains a Security News section that lists security articles of 
interest. There are related security tools and links.
You can access Cisco Security Intelligence Operations at this URL:
Cisco Security Intelligence Operations is also a repository of information for individual signatures, 
including signature ID, type, structure, and description.
You can search for security alerts and signatures at this URL:
New and Changed Information 
Cisco IPS 6.0(4)E2 includes the following new features:
The S339 signature update is built in to the E2 engine update. You cannot download S399 separately.
The E2 engine update contains the following new and changed engines:
P2P engine—The existing Peer-to-Peer signatures have been organized in to a dedicated, 
optimized engine that lets the sensor monitor all 65, 536 ports in both the TPC and UDP 
protocols for peer-to-peer traffic. The P2P engine is enabled by default and because of the 
implementation style of this engine, you cannot create custom P2P signatures.
Fixed Depth All Ports Inspection engine—A series of new engines similar to the String TCP 
engine has been developed to provide a more optimized approach to monitoring all ports. The 
fixed inspection engines—Fixed TPC, Fixed UDP, and Fixed ICMP—provide monitoring for all 
ports (TCP and UDP) by default. They inspect traffic in a stream mode per AaBb tuple to a