<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting up sensor in inline interface pair mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/setting-up-sensor-in-inline-interface-pair-mode/m-p/2125324#M54319</link>
    <description>&lt;P&gt;I have never set up a sensor in inline interface pair mode, and I had a couple of questions about it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is my understanding that traffic from one vlan would be forwarded to another through the sensor (and then you would set up your ispection policies).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how then would you set up the SPAN or capture ACLs on the switching side? A monitor session will put a port in a disabled mode (although I think you can use the monitor session x destination &amp;lt;interface&amp;gt; ingress to allow traffic from it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or would you use the &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport capure &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command with FSPAN on both interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice would be great&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:50:49 GMT</pubDate>
    <dc:creator>Colin Higgins</dc:creator>
    <dc:date>2019-03-10T12:50:49Z</dc:date>
    <item>
      <title>Setting up sensor in inline interface pair mode</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-sensor-in-inline-interface-pair-mode/m-p/2125324#M54319</link>
      <description>&lt;P&gt;I have never set up a sensor in inline interface pair mode, and I had a couple of questions about it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is my understanding that traffic from one vlan would be forwarded to another through the sensor (and then you would set up your ispection policies).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how then would you set up the SPAN or capture ACLs on the switching side? A monitor session will put a port in a disabled mode (although I think you can use the monitor session x destination &amp;lt;interface&amp;gt; ingress to allow traffic from it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or would you use the &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport capure &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command with FSPAN on both interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice would be great&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-sensor-in-inline-interface-pair-mode/m-p/2125324#M54319</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-10T12:50:49Z</dc:date>
    </item>
    <item>
      <title>Setting up sensor in inline interface pair mode</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-sensor-in-inline-interface-pair-mode/m-p/2125325#M54321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For inline-pair, configuration should be something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming switchport to be 1/1 and 1/2. IPS port Gig0/0 and Gig 0/1&lt;/P&gt;&lt;P&gt;1/1 and Gig0/0 should be in one vlan, lets say 800.&lt;/P&gt;&lt;P&gt;1/2 and Gig0/1 should be other vlan, lets say 810.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switchport config:&lt;/P&gt;&lt;P&gt;1/1&lt;/P&gt;&lt;P&gt;switchport&lt;/P&gt;&lt;P&gt;switchport access vlan 800&lt;/P&gt;&lt;P&gt;switchport mode acess&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1/2&lt;/P&gt;&lt;P&gt;switchport&lt;/P&gt;&lt;P&gt;switchport access vlan 810&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All traffic from vlan 800 will be sent to port under vlan 810 and vice-versa after inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sawan Gupta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 04:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-sensor-in-inline-interface-pair-mode/m-p/2125325#M54321</guid>
      <dc:creator>sawgupta</dc:creator>
      <dc:date>2012-12-10T04:53:05Z</dc:date>
    </item>
  </channel>
</rss>

