1 Reply Latest reply on Jul 14, 2011 4:15 PM by SGROSSEN

    How to Deploy Different UDS to Different IPS Sensors?

      I have 3 Intrushield IPS sensors managed by a single NSP. 

       

      I would like to deploy different UDS to each IPS sensor, but it looks like I can only deploy all UDS at once by "exporting to manager"?

       

      If I create an adminisrative domain, will that let me manage differnet UDS per sensor?

       

      The scenario is as follows:

       

      • I have 3 UDS.

       

      • I have 3 IPS sensors managed by a single NSP.

       

      • I want to push UDS #1 to IPS sensor #1

       

      • I want to push UDS #2 to IPS sensor #2

       

      • I want to push UDS #3 to IPS sensor #3.

       

      When I "export to manager" in UDS Editor, it updates all IPS senors with all UDS signatures, which is not what I want.

       

      I've thought of maybe disconnecting one IPS sensor at a time, but am not 100% sure that won't get clobbered on the next automated signature update.  That's also a support nightmware as well.

        • 1. Re: How to Deploy Different UDS to Different IPS Sensors?
          SGROSSEN

          WHen the UDS is pushed, it automatically populates the default policies.  You will need to clone the Policy, or create a new policy.  At this point you can disable the UDS sig you want per individual policies.

           

          You can also use rulesets to create a new Ruleset and bubble that up to a new policy.  The rulesets give you control over individual attacks in the policy, and you can make your UDS decisions at that time.