<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue - Inline VLAN pair IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195940#M53932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunetly I cannot check that website from work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you add another switch into the mix you have to make sure traffic does not get routed trough the switch, it must go over the IPS first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically configure the trunks to allow only the vlan necessarys and then the IPS supporting both of them so traffic must&amp;nbsp; go over the Trunk link &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that I could help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Mar 2013 19:33:10 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-03-20T19:33:10Z</dc:date>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195935#M53927</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an issue with an 4255 IPS using an inline VLAN pair. Here's the rough sketch of the topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1&lt;/P&gt;&lt;P&gt;port 1 access vlan 10 - PC (10.20.30.2/24)&lt;/P&gt;&lt;P&gt;port 48 trunk to SW2 - all vlans allowed and forwarding&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW2&lt;/P&gt;&lt;P&gt;port 48 trunk to SW1 - all vlans allowed and forwarding&lt;/P&gt;&lt;P&gt;port 1 trunk allowed vlan 10,20 to IPS g0/1 configured in inline VLAN pair; assigned to sensor etc.&lt;/P&gt;&lt;P&gt;SVI vlan 20 for network 10.20.30.1/24 (up/up)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm unable to ping SVI from PC. Anyone have any suggestions? Running packet display on IPS interface I only see BPDUs hitting the interface. VTP is enabled but pruning is disabled. Both vlans exist on both switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm only seeing ARP requests from SVI on the IPS, but no replies coming from the remote switch.&lt;/P&gt;&lt;P&gt;Alternatively the PC is sending ARP requests to the SVI IP, but those aren't getting resolved, nor are they getting to the IPS interface.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195935#M53927</guid>
      <dc:creator>yuriy-sokhan</dc:creator>
      <dc:date>2019-03-10T12:55:37Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195936#M53928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Yuriy&lt;/P&gt;&lt;P&gt;So Topology is something like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC-----ACCESSPORT----SW1----TRUNK----SWITCH2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS Inile vlan pair &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The thing is that if you already allow the vlans on the trunk link then traffic will not get inspect by the IPS, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see what I mean, you must force it to go to the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if I was clear enough&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 07:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195936#M53928</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T07:03:19Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195937#M53929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the topology is &lt;/P&gt;&lt;P&gt;PC-----ACCESSPORT----SW1----TRUNK----SW2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC is on SW1 - vlan 10&lt;/P&gt;&lt;P&gt;SVI/Default gateway for PC is on SW2.- vlan 20&lt;/P&gt;&lt;P&gt;IPS is on SW2 - trunk vlans allowed 10,20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought since the VLANs must be bridged in order for PC to reach SVI, this would force IPS to pick up the traffic as nothing else would respond to the ARP request. Could you please explain this a little more? SW1 doesn't have any SVIs and is layer 2 only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am i supposed to only allow VLAN 10 over the trunk? Should VLAN 20 not exist on SW1?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 11:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195937#M53929</guid>
      <dc:creator>yuriy-sokhan</dc:creator>
      <dc:date>2013-03-20T11:19:47Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195938#M53930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was trying to find a way to explain this to you when I found the following blog ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read and if you have any questions let me now.. If not then you can mark it as answered&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://fengnet.com/book/CCIE.Professional.Development.Series.Network.Security.Technologies.and.Solutions/final/ch20lev1sec14.html" style="line-height: 21px; color: #0068cf; cursor: pointer; font-family: Calibri, sans-serif; font-size: 15px; background-color: #ffffff;" target="_blank"&gt;http://fengnet.com/book/CCIE.Professional.Development.Series.Network.Security.Technologies.and.Solutions/final/ch20lev1sec14.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 16:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195938#M53930</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T16:49:07Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195939#M53931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've seen the tutorials where the devices are connected to the same switch, but what about adding another switch into the mix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Diagram:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://imgur.com/idZuVdL"&gt;http://imgur.com/idZuVdL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any extra configuration required in order for PC to ping its default gateway (SVI on SW2) ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 17:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195939#M53931</guid>
      <dc:creator>yuriy-sokhan</dc:creator>
      <dc:date>2013-03-20T17:18:57Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195940#M53932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunetly I cannot check that website from work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you add another switch into the mix you have to make sure traffic does not get routed trough the switch, it must go over the IPS first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically configure the trunks to allow only the vlan necessarys and then the IPS supporting both of them so traffic must&amp;nbsp; go over the Trunk link &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that I could help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 19:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195940#M53932</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-20T19:33:10Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195941#M53933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think what Yuri is saying that a packet from PC connected to switch 1 VLAN 10 should pass through IPS If IPS trunk allows VLANs 10 and 20 and PCs default gateway is VLAN20 SVI defined on SW2. But it does not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 19:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195941#M53933</guid>
      <dc:creator>Alexander Adams</dc:creator>
      <dc:date>2013-03-21T19:11:22Z</dc:date>
    </item>
    <item>
      <title>Issue - Inline VLAN pair IPS</title>
      <link>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195942#M53934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok Bottom line just permit vlan 10 between the switch trunk to the other switch,&lt;/P&gt;&lt;P&gt;From the switch to the IPS trunk both vlan 10 and 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 19:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-inline-vlan-pair-ips/m-p/2195942#M53934</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-21T19:32:16Z</dc:date>
    </item>
  </channel>
</rss>

