 Reviews:
·Comcast
·AT&T Midwest
1 edit | reply to Jan Janowski
Re: RVS 4000 Support email to Cisco Good Going! Most of my complaints are not complicated issues.
1. Turn on Logging. 2. Indicate in log which level (0-7) each entry is configured to, so you can easily deteremine which log level to enable/disable. At present, you can't determine which log level belongs with which entry... 3. Turn off (or make it switchable) IPS Update Reminder Nags. This works in conjunction with: 4. Update IPS in a timely fashion, and have it report correct date. 5. Turn off VPN restart updates to logs when VPN is not used. 6. Printing out Configuration Pages EATS BLUE INK! Go back to transparent B&W only, with a small neat Color Logo, and Have Each Configuration Page Print onto one sheet of paper (Presently it doesn't print out any text that is off screen) -- In other words, GO BACK to V1.2.11 style printout!
These are not earth shattering, but a bit annoying... -- Looking for 1939 Indian Motocycle |
|
 Reviews:
·Comcast
·AT&T Midwest
1 edit | reply to Jan Janowski
V1.41 IPS file Released! Yesterday, it seems:
Version: 1.41 Total Rules: 1098
In this signature, we addressed the exploits/vulnerabilities and applications as below:
-EXPLOIT MS Video ActiveX Control Stack Buffer Overflow A buffer overflow vulnerability exists in Microsoft DirectShow. The flaw is due to the way Microsoft Video ActiveX Control parses image files. An attacker can persuade the target user to open a malicious web page to exploit this vulnerability.
-EXPLOIT Oracle Database Workspace Manager SQL Injection Multiple SQL injection vulnerabilities exist in Oracle Database Server product. The vulnerabilities are due to insufficient sanitization of input parameters in the Oracle Workspace Manager component. A remote attacker with valid user credentials may leverage these vulnerabilities to inject and execute SQL code with escalated privilegesof SYS or WMSYS account.
Support P2P application named uTorrent up to version 1.7.2.
Signature content for 1.41 ======================================================================== New Added signature(s): 1053635 EXPLOIT MS Video ActiveX Control Stack Buffer Overflow -1 1053636 EXPLOIT MS Video ActiveX Control Stack Buffer Overflow -2 1053632 EXPLOIT Oracle Database Workspace Manager SQL Injection -1 1053633 EXPLOIT Oracle Database Workspace Manager SQL Injection -2 1053634 EXPLOIT Oracle Database Workspace Manager SQL Injection -3
Modified signature(s): 1051783 P2P Gnutella Connect 1051212 P2P Gnutella Get file 1051785 P2P Gnutella UDP PING 2 1051997 P2P Gnutella Bearshare file transfer with UDP 1052039 P2P Gnutella OK 1052637 P2P Foxy Get file
Deleted signature(s): 1050521 Worm.Klez.E1 - 1 1050522 Worm.Klez.E1 - 2 1050523 Worm.Klez.E1 - 3 1050524 Worm.Klez.E2 - 1 1050525 Worm.Klez.E2 - 2 1050526 Worm.Klez.E2 ¡V 3 1050536 Worm.Blaster.B - 1 1050537 Worm.Blaster.B - 2 1050538 Worm.Blaster.B - 3 1050539 Worm.Blaster.C - 1 1050540 Worm.Blaster.C - 2 1050541 Worm.Blaster.C - 3
Number of rules in each category: ======================================================================== DoS/DDoS 51 Buffer Overflow: 241 Access Control: 92 Scan: 41 Trojan Horse: 62 Misc: 3 P2P: 40 Instant Messenger: 121 Vrus/Worm: 410 Web Attacks: 37
And when loaded, the correct date of load was attached to it!!! No more IPS date of 1969!!! ! -- Looking for 1939 Indian Motocycle |
|
 ironwalker World RenownedPremium,MVM join:2001-08-31 Keansburg, NJ | reply to Jan Janowski
Re: RVS 4000 Support email to Cisco Hey guys, I lost the download page in bookmarks for firmware and ips signature downloads, can someone please post them or the page links?
Thank you. |
|
|
|
 Reviews:
·Comcast
·AT&T Midwest
| reply to Jan Janowski You'll have to have a login....
»tools.cisco.com/support/download···82414013 -- Looking for 1939 Indian Motocycle |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 | reply to Jan Janowski
Re: V1.41 IPS file Released! Wow. How long now did it take to update the IPS? I'm just glad a new one was finally released. Even if it did take an unacceptable amount of time. |
|
 Reviews:
·Comcast
·AT&T Midwest
| reply to Jan Janowski
Re: RVS 4000 Support email to Cisco Dustyn.... I'd guestimate it took 30 seconds to update the IPS.... Did it without moving router.
Usually, because of the 'default to Factory specs' step prior to upgrading, I remove router to a stand alone system for firmware upgrading, but for IPS I just go to router, and point it at the update, and let it update itself... -- Looking for 1939 Indian Motocycle |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 1 edit | You are correct. IPS updating in about 30 seconds. No reboot required either. Firmware Version: V1.1.14 |
|
 Link LoggerPremium,MVM join:2001-03-29 Calgary, AB kudos:3 Reviews:
·Shaw
| reply to Jan Janowski Bad news, logging still isn't fixed. Here is a clip of an email from one of our clients who was testing a new firmware for the RVS4000:
quote: You were right to have doubts. It was not fixed. Same problem. I installed the new firmware and still no incoming traffic. The people at Cisco checking the new firmware upgrade had port forwarding setup in a way that produced erroneous reports of incoming traffic. They are discussing with their project engineer, and said they would get back to me, but they also mentioned that it might be a "product limitation".
There are times when Linksys/Cisco drives me crazy and I swear they don't have a QA group or product managers who know much about routers/firewalls (about logging at least).
Blake -- Vendor: Author of Link Logger which is a traffic analysis and firewall logging tool |
|
 ironwalker World RenownedPremium,MVM join:2001-08-31 Keansburg, NJ | Thanks, I will pass on this since I do not use the email function and the logging itself does not work correctly still.
Thanks. |
|
 DustynPremium join:2003-02-26 Ontario, CAN kudos:7 Reviews:
·Rogers Hi-Speed
| reply to Jan Janowski said by Jan Janowski:Has anyone done in depth testing on this version yet? I'm also waiting for user info on the latest firmware release and how it's performing. |
|
 Reviews:
·Comcast
·AT&T Midwest
3 edits | reply to Jan Janowski With New V1.41 (Not New, most recent) IPS, and New Firmware 1.3.0.5 I'm still getting random:
Your Signature Version is beyond ____ days. Please Update it!
and the other one that seems to be connected to VPN (And I'm Not doing VPN!! )
-IPSEC EVENT: KLIPS device ipsec0 shut down
I've not encountered any operational issues, but I'm doing plain vanilla operations. and I haven't encountered anything unusual or worse than the prior version of the firmware/IPS. Basically -- Reason why I'm using RVS4000 to provide Gigabit file sharing between a couple computers..... It seems to work that way..
However, I believe Blake has coommented it is as broken as the previous version was...
-- Looking for 1939 Indian Motocycle |
|