A.disable Zone-Based Firewall as the two features are not compatible
B.disable Cisco Express Forwarding as the two features are not compatible
C.generate a certificate and export on Cisco.com to receive a signature update
D.import the public RSA key from the Cisco IPS team that allows the router to verify that a signatureupdate (which was signed by this key) comes from Cisco