<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virtual IPS/IDS design question. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753943#M44593</link>
    <description>&lt;P&gt;Hi!&amp;nbsp;I'm having some problems with understanding the design of&amp;nbsp;virtual IPS/IDS.&lt;BR /&gt;I know how to do it with hardware IPS/IDS, when you have one physical interfaces specified to handle traffic and another physical interface to to send inspected traffic back to Core.&lt;/P&gt;&lt;P&gt;My question is how do people do it with virtual firewall? I mean how it is possible to configure a server running on VMWare to receive SPAN session (in IDS case) or something like that.&lt;/P&gt;&lt;P&gt;I hope I can clarify my concern.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:27:20 GMT</pubDate>
    <dc:creator>David Kleberson</dc:creator>
    <dc:date>2019-03-10T13:27:20Z</dc:date>
    <item>
      <title>Virtual IPS/IDS design question.</title>
      <link>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753943#M44593</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;I'm having some problems with understanding the design of&amp;nbsp;virtual IPS/IDS.&lt;BR /&gt;I know how to do it with hardware IPS/IDS, when you have one physical interfaces specified to handle traffic and another physical interface to to send inspected traffic back to Core.&lt;/P&gt;&lt;P&gt;My question is how do people do it with virtual firewall? I mean how it is possible to configure a server running on VMWare to receive SPAN session (in IDS case) or something like that.&lt;/P&gt;&lt;P&gt;I hope I can clarify my concern.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753943#M44593</guid>
      <dc:creator>David Kleberson</dc:creator>
      <dc:date>2019-03-10T13:27:20Z</dc:date>
    </item>
    <item>
      <title>You can actually do both. If</title>
      <link>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753944#M44594</link>
      <description>&lt;P&gt;You can actually do both. If you just want to monitor (IDS) then you will have to dedicate a physical port on your VM server and span traffic to it. For more info on that check this link:&lt;/P&gt;&lt;P&gt;&lt;A href="http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1004099"&gt;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1004099&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you want to place the virtual appliance inline, then you will have to dedicate two physical ports from your VM server. One of those ports will be used for the&amp;nbsp;&lt;STRONG&gt;outside zone&amp;nbsp;&lt;/STRONG&gt;and the other for your&amp;nbsp;&lt;STRONG&gt;inside zone.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 19:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753944#M44594</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-09-16T19:32:39Z</dc:date>
    </item>
    <item>
      <title>Neno, thank you for your</title>
      <link>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753945#M44595</link>
      <description>&lt;P&gt;Neno, thank you for your reply. Does it mean that I have to sacrifice 1 or 2 physical ports of a host that is running VMware or HyperV?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2015 17:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753945#M44595</guid>
      <dc:creator>David Kleberson</dc:creator>
      <dc:date>2015-09-21T17:38:56Z</dc:date>
    </item>
    <item>
      <title>Yes, otherwise you can't</title>
      <link>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753946#M44596</link>
      <description>&lt;P&gt;Yes, otherwise you can't really put it truly inline if other hosts/vlans are about to traverse around it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2015 00:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/virtual-ips-ids-design-question/m-p/2753946#M44596</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-09-22T00:33:38Z</dc:date>
    </item>
  </channel>
</rss>

