D-11
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
OL-24002-01
Appendix D Upgrading, Downgrading, and Installing System Images
Downgrading the Sensor
user-name: tester
password: <hidden>
file-copy-protocol: ftp default: scp
-----------------------------------------------
sensor(config-hos-ena)#
Step 8
Exit automatic upgrade submode.
sensor(config-hos-ena)#
exit
sensor(config-hos)#
exit
Apply Changes:?[yes]:
Step 9
Press
Enter
to apply the changes or type
no
to discard them.
For More Information
•
For a list of supported FTP and HTTP/HTTPS servers, see
Supported FTP and HTTP/HTTPS
Servers, page D-3
.
•
For the procedure for adding a remote host to the trusted hosts list, for IDM refer to
Defining Known
Hosts Keys
, for IME refer to
Defining Known Host Keys
, and for the CLI, refer to
Adding Hosts to
the SSH Known Hosts List.
Downgrading the Sensor
Caution
You cannot use the
downgrade
command to revert to a previous major or minor version, for example,
from Cisco IPS 7.1 to 7.0. You can only use the
downgrade
command to downgrade from the latest
signature update or signature engine update. To revert to 7.0, you must reimage the sensor.
Note
You cannot downgrade the sensor using the recovery partition. To downgrade to an earlier version, you
must install the appropriate system image file (.img file).
Use the
downgrade
command to remove the last applied signature upgrade or signature engine upgrade
from the sensor.
To remove the last applied signature update or signature engine update from the sensor, follow these
steps:
Step 1
Log in to the sensor using an account with administrator privileges.
Step 2
Enter global configuration mode.
sensor#
configure terminal
Step 3
If there is no recently applied service pack or signature update, the
downgrade
command is not
available.
sensor(config)#
downgrade
No downgrade available.
sensor(config)#