Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

How do I replace an old IPS Device with a new IPS Device?

    • Updated:
    • Product/Version:
    • TippingPoint IPS N-series All
    • TippingPoint IPS NX-series All
    • TippingPoint IPS S-series All
    • TippingPoint NGFW All
    • TippingPoint SMS All
    • TippingPoint TPS All
    • TippingPoint Virtual SMS
    • TippingPoint Virtual TPS All
    • Platform:
Summary
The SMS provides a convenient option that allows you to replace an existing IPS device and have the new device function exactly the same as the old device. When you replace a device, the events from the previous device are preserved. However previous installed TOS versions, rollback versions and snapshot are reset using the new (replaced) device as a starting point.
Details
Public

IPS Device Replacement Limitations

The Device replace feature has the following limitations:

N/NX-Platform Devices:

  • N/NX Platform devices can replace any device, but may have data loss.
  • Only N/NX Platform devices can replace other N/NX Platform device
  • RADIUS authentication settings and servers remain only if the replacement devices support
  • RADIUS authentication (N-Platform or NX-Platform devices running TOS v3.7.0 or later).
  • A replacement device does not inherit device users. All device users must be added back manually.
  • You cannot replace FIPS Settings on the device.

 

Profile Distribution:

Auto redistribution profiles is NOT supported

Port configuration considerations

When you replace a device with another device that has a different port configuration, the SMS may attempt to push the port configuration for the old device to the new device. If this happens, unmanage the device, use the CLI or LSM to disable auto-negotiate for each port, and then remanage the device. You will need to redistribute any profile that was distributed to the device after you remanage it.

IPS Device Replacement Considerations

If you are replacing the same model with another model and both devices have the same TOS, the one-to-one replacement is straightforward. The following replacement options have specific issues to take into consideration:

Segments

Data loss occurs if the new device has fewer segments than the old device. For example, when a device with four segments is replaced by a device with two segments, events and settings related to the additional segments, if configured on the original device, are lost.

DDoS

Possible data loss occurs if the new device does not support DDoS and the old device is configured for DDoS.

Different Models

New model cannot use same IP address as old model: If the old model is still online, you cannot use the same IP address and must choose a different one for the new model. If the TOS versions are not the same, you must upgrade to the newer version. After you upgrade your IPS device, you can give the old device and new IP Address and place it in another area of the network.

New model has more segments: Because the models are not the same and the new device has extra segments, the new segments are not configured. Extra segments are placed in the Default segment group.

New model has fewer segments: Because the models are not the same and the new device has fewer segments, the SMS cannot copy all segment/port setting to the new device. Therefore, the configuration of the common segments is copied and the remaining segment are dropped or removed from the SMS.

How To: Replace a Device

  1. Remove the new replacement IPS from the box and complete the Out of Box Experience (OBE) instructions using the old IPS address for the new one.
  2. If the old model and new model are not the same and/or the TOS versions are different, refer to the "IPS Device Replacement Considerations" section above.
  3. Log in to the SMS from a client.
  4. On the SMS toolbar, navigate to the Devices->All Devices tab screen.
  5. On the All Devices screen, select the device to be replaced and do one of the following:
    • Right-click and select Edit -> Replace Device.
    • On the top menu bar, select Edit->Details->Replace Device.
  6. After Devices - Replace Device dialog displays, enter the information for the new IPS device and click OK.
  7. If all of the supplied information is correct, the models are the same and the TOS versions are the same, a progress dialog appears. If the models or TOS versions are not the same, refer to the "IPS Device Replacement Considerations "section of the SMS User Guide.
  8. When the replacement process is complete, a dialog appears and directs you to redistribute the appropriate versions of the IPS profiles.

Reference: SMS User Guide

Premium
Internal
Rating:
Category:
Configure; Troubleshoot; Deploy
Solution Id:
TP000086239
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.