<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS design and implementation question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-design-and-implementation-question/m-p/1760026#M56171</link>
    <description>&lt;P&gt;&lt;IMG src="http://www.cisco.com/en/US/i/100001-200000/110001-120000/114001-115000/114002.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in process of implementing an IPS in our network.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS will be located behind the ASA firewall.&amp;nbsp; For example &lt;STRONG&gt;&lt;EM&gt; Edge router/switch&amp;nbsp; &amp;gt; IPS firewall &amp;gt;&amp;nbsp; ASA firewall &amp;gt; Entry/Exit router . &lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; We are going to have a hardware bypass switch for the IPS firewall.&amp;nbsp;&amp;nbsp; I am new to IPS and I am not entirely sure I wanted to clarify few things. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My proposed design is&amp;nbsp; ASA plugs into 1 port of hardware bypass switch. 2nd port on hardware bypass switch connects to edge router/switch.&amp;nbsp; Remaining two ports will connect to the g0/0 and g0/1 will be inline pair of IPS.&amp;nbsp;&amp;nbsp;&amp;nbsp; Firewalls are setup in active failover group at the moment but as only have 1 IPS we are not intending to use the IPS when primary ASA firewall is down.&amp;nbsp;&amp;nbsp; So when the primary firewall is down our backup firewall will take over but traffic won't be passed through the IPS.&amp;nbsp;&amp;nbsp; I have few questions/queries about this setup.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Can I create another inline pair g0/2 and g0/3 and connect backup firewall to that?&amp;nbsp; When the backup firewall takes over can it use the IPS and pass the traffic via IPS along our primary/active infrastructure?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; If I do not connect the backup firewall to IPS' 2nd inline pair,&amp;nbsp; In this scenario traffic will flow through backup asa via backup infrastructure (backup edge router so on and so forth)&amp;nbsp; automatic change over would still take place when the primary ASA fails as long as two ASAs have heartbeat packets between them? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Suppose if hardware bypass switch solution is not implemented and If I do not use the 2nd inline pair and just use the IPS with primary firewall, in case of IPS hardware failure would secondary firewall take over automatically.&amp;nbsp; This is confusing me a great deal. Basically what I am proposing is that we don't use the hardware bypass.&amp;nbsp; Connect the IPS between edge router and active ASA.&amp;nbsp; Active ASA will be part of the fail over group with backup ASA.&amp;nbsp; Now if the IPS sensor has a hardware failure, would primary ASA know somehow about it?&amp;nbsp; Will this scenario trigger the automatic switch over to backup ASA firewall?&amp;nbsp; Is this even possible? If so what configuration is needed to implement it.&amp;nbsp; Or would primary ASA continue to send the traffic out to IPS eventhough its dead.&amp;nbsp; Has ASA got some sort of built it mechanism like UDLD to detect the hardware failure for connected device?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any of the setup options do I need to worry about Vlans?&amp;nbsp; how does IPS fit in with multiple vlans on the local segment?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would really appreciate any help with my questions. Thanks. Regards. &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:29:50 GMT</pubDate>
    <dc:creator>desaijaimin</dc:creator>
    <dc:date>2019-03-10T12:29:50Z</dc:date>
    <item>
      <title>IPS design and implementation question</title>
      <link>https://community.cisco.com/t5/network-security/ips-design-and-implementation-question/m-p/1760026#M56171</link>
      <description>&lt;P&gt;&lt;IMG src="http://www.cisco.com/en/US/i/100001-200000/110001-120000/114001-115000/114002.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am in process of implementing an IPS in our network.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS will be located behind the ASA firewall.&amp;nbsp; For example &lt;STRONG&gt;&lt;EM&gt; Edge router/switch&amp;nbsp; &amp;gt; IPS firewall &amp;gt;&amp;nbsp; ASA firewall &amp;gt; Entry/Exit router . &lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; We are going to have a hardware bypass switch for the IPS firewall.&amp;nbsp;&amp;nbsp; I am new to IPS and I am not entirely sure I wanted to clarify few things. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My proposed design is&amp;nbsp; ASA plugs into 1 port of hardware bypass switch. 2nd port on hardware bypass switch connects to edge router/switch.&amp;nbsp; Remaining two ports will connect to the g0/0 and g0/1 will be inline pair of IPS.&amp;nbsp;&amp;nbsp;&amp;nbsp; Firewalls are setup in active failover group at the moment but as only have 1 IPS we are not intending to use the IPS when primary ASA firewall is down.&amp;nbsp;&amp;nbsp; So when the primary firewall is down our backup firewall will take over but traffic won't be passed through the IPS.&amp;nbsp;&amp;nbsp; I have few questions/queries about this setup.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Can I create another inline pair g0/2 and g0/3 and connect backup firewall to that?&amp;nbsp; When the backup firewall takes over can it use the IPS and pass the traffic via IPS along our primary/active infrastructure?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; If I do not connect the backup firewall to IPS' 2nd inline pair,&amp;nbsp; In this scenario traffic will flow through backup asa via backup infrastructure (backup edge router so on and so forth)&amp;nbsp; automatic change over would still take place when the primary ASA fails as long as two ASAs have heartbeat packets between them? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Suppose if hardware bypass switch solution is not implemented and If I do not use the 2nd inline pair and just use the IPS with primary firewall, in case of IPS hardware failure would secondary firewall take over automatically.&amp;nbsp; This is confusing me a great deal. Basically what I am proposing is that we don't use the hardware bypass.&amp;nbsp; Connect the IPS between edge router and active ASA.&amp;nbsp; Active ASA will be part of the fail over group with backup ASA.&amp;nbsp; Now if the IPS sensor has a hardware failure, would primary ASA know somehow about it?&amp;nbsp; Will this scenario trigger the automatic switch over to backup ASA firewall?&amp;nbsp; Is this even possible? If so what configuration is needed to implement it.&amp;nbsp; Or would primary ASA continue to send the traffic out to IPS eventhough its dead.&amp;nbsp; Has ASA got some sort of built it mechanism like UDLD to detect the hardware failure for connected device?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For any of the setup options do I need to worry about Vlans?&amp;nbsp; how does IPS fit in with multiple vlans on the local segment?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would really appreciate any help with my questions. Thanks. Regards. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-design-and-implementation-question/m-p/1760026#M56171</guid>
      <dc:creator>desaijaimin</dc:creator>
      <dc:date>2019-03-10T12:29:50Z</dc:date>
    </item>
  </channel>
</rss>

