<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SPAN Configuration for IDSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695758#M65305</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When running a FWSM in a 6500, you don't need to use a SPAN session to send traffic to the FWSM.&amp;nbsp; To send traffic through the FWSM, use the "firewall" set of commands in the 6500 switch configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I recommend reading the section "&lt;STRONG&gt;Assigning VLANs to the Firewall Services Module&lt;/STRONG&gt;" from the&lt;SPAN&gt; &lt;/SPAN&gt;&lt;STRONG&gt;FWSM 4.1 Configuration Guide&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/en/US/customer/docs/security/fwsm/fwsm41/configuration/guide/switch_f.html#wp1175820"&gt;http://www.cisco.com/en/US/customer/docs/security/fwsm/fwsm41/configuration/guide/switch_f.html#wp1175820&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There's also an example of these commands in the "&lt;STRONG&gt;FWSM Basic Configuration Example&lt;/STRONG&gt;" here:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/en/US/customer/products/hw/modules/ps2706/products_configuration_example09186a00808b4d9f.shtml#sw"&gt;http://www.cisco.com/en/US/customer/products/hw/modules/ps2706/products_configuration_example09186a00808b4d9f.shtml#sw&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A similar command exists for the IDSM ("intrusion-detection module"), for use in certain configurations.&amp;nbsp; You can read more here, in the "&lt;STRONG&gt;Configuring IDSM-2&lt;/STRONG&gt;" section of the&lt;SPAN&gt; &lt;/SPAN&gt;&lt;STRONG&gt;IPS 6.1 Configuration Guide for CLI&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_idsm2.html#wp1030828"&gt;http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_idsm2.html#wp1030828&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt;If nothing else, using these commands could free up the 2 available SPAN sessions for other use (such as a NAM module).&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Apr 2011 01:59:52 GMT</pubDate>
    <dc:creator>mikecrowe4ICS_2</dc:creator>
    <dc:date>2011-04-11T01:59:52Z</dc:date>
    <item>
      <title>SPAN Configuration for IDSM</title>
      <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695757#M65304</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have IDSM / FWSM running in our 6500 Switch, the FWSM is in transparent mode and for IDSM we configured one SPAN Port.&lt;/P&gt;&lt;P&gt;Right now we have one requirement for SPAN configuration. currently the 6500 with the current SUP has limitation for only 2 SPAN Sessions, &lt;/P&gt;&lt;P&gt;And we are using both, one is for FWSM and the second one for IDSM.&lt;/P&gt;&lt;P&gt;Any one can help and suggest for another option?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695757#M65304</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2019-03-10T12:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: SPAN Configuration for IDSM</title>
      <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695758#M65305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When running a FWSM in a 6500, you don't need to use a SPAN session to send traffic to the FWSM.&amp;nbsp; To send traffic through the FWSM, use the "firewall" set of commands in the 6500 switch configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I recommend reading the section "&lt;STRONG&gt;Assigning VLANs to the Firewall Services Module&lt;/STRONG&gt;" from the&lt;SPAN&gt; &lt;/SPAN&gt;&lt;STRONG&gt;FWSM 4.1 Configuration Guide&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/en/US/customer/docs/security/fwsm/fwsm41/configuration/guide/switch_f.html#wp1175820"&gt;http://www.cisco.com/en/US/customer/docs/security/fwsm/fwsm41/configuration/guide/switch_f.html#wp1175820&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There's also an example of these commands in the "&lt;STRONG&gt;FWSM Basic Configuration Example&lt;/STRONG&gt;" here:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/en/US/customer/products/hw/modules/ps2706/products_configuration_example09186a00808b4d9f.shtml#sw"&gt;http://www.cisco.com/en/US/customer/products/hw/modules/ps2706/products_configuration_example09186a00808b4d9f.shtml#sw&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A similar command exists for the IDSM ("intrusion-detection module"), for use in certain configurations.&amp;nbsp; You can read more here, in the "&lt;STRONG&gt;Configuring IDSM-2&lt;/STRONG&gt;" section of the&lt;SPAN&gt; &lt;/SPAN&gt;&lt;STRONG&gt;IPS 6.1 Configuration Guide for CLI&lt;/STRONG&gt;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_idsm2.html#wp1030828"&gt;http://www.cisco.com/en/US/docs/security/ips/6.1/configuration/guide/cli/cli_idsm2.html#wp1030828&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt;If nothing else, using these commands could free up the 2 available SPAN sessions for other use (such as a NAM module).&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 01:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695758#M65305</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2011-04-11T01:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: SPAN Configuration for IDSM</title>
      <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695759#M65306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for prompt reply.&lt;/P&gt;&lt;P&gt;The configuration iam looking is for IDSM, FWSM already configured.&lt;/P&gt;&lt;P&gt;we have two options to configure IDSM in 6500, SPAN and VACL Capture.&lt;/P&gt;&lt;P&gt;Is there any third option available for IDSM configuration? we need one span session for some Monitoring tool, and there are already 2 session in the sup configured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 04:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695759#M65306</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2011-04-11T04:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: SPAN Configuration for IDSM</title>
      <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695760#M65307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;FWSM already configured.&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;we need one span session for some Monitoring tool, and &lt;STRONG&gt;there are already 2 session in the sup configured&lt;/STRONG&gt;.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;S&gt;Actually, that's why I mentioned the FWSM configuration.&amp;nbsp; You don't need to use SPAN in conjuntion with the FWSM.&amp;nbsp; In fact, I've never seen it used that way.&lt;/S&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My apologies, I didn't realize the &lt;A href="http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml#FWSM"&gt;FWSM is automatically using a SPAN session&lt;/A&gt;, which isn't listed in the config.&amp;nbsp; Well, you won't &lt;STRONG&gt;need&lt;/STRONG&gt; SPAN for the IDSM, at least for most configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;we have two options to configure IDSM in 6500, SPAN and VACL Capture.&lt;/P&gt;&lt;P&gt;Is there any third option available for IDSM configuration?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;You can see the supported configurations for the IDSM-2 in the "&lt;STRONG&gt;Configuring IDSM-2&lt;/STRONG&gt;" section of the &lt;STRONG&gt;IPS Configuration Guide for CLI, &lt;/STRONG&gt;found here&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/customer/docs/security/ips/7.0/configuration/guide/cli/cli_idsm2.html#wp1030694"&gt;http://www.cisco.com/en/US/customer/docs/security/ips/7.0/configuration/guide/cli/cli_idsm2.html#wp1030694&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The options include:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SPAN&lt;/LI&gt;&lt;LI&gt;VACL Capture&lt;/LI&gt;&lt;LI&gt;EtherChannel Load Balancing (ECLB) with VACL Capture&lt;/LI&gt;&lt;LI&gt;Inline Interface Pairs&lt;/LI&gt;&lt;LI&gt;ECLB with Inline Interface Pairs&lt;/LI&gt;&lt;LI&gt;Inline VLAN Pairs&lt;/LI&gt;&lt;LI&gt;ECLB with Inline VLAN Pairs&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you looking to put the IPS/IDS in "inline" mode?&amp;nbsp; Or would you like to keep it as promiscuous only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Michael Crowe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 05:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695760#M65307</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2011-04-11T05:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: SPAN Configuration for IDSM</title>
      <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695761#M65308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Michael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IDSM is in &lt;SPAN&gt; promiscuous&amp;nbsp; mode. we do not want to put it inline.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 06:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695761#M65308</guid>
      <dc:creator>syedaltaf.shah</dc:creator>
      <dc:date>2011-04-11T06:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: SPAN Configuration for IDSM</title>
      <link>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695762#M65309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then you will want to use a VACL capture.&amp;nbsp; The procedure can be found here:&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/customer/docs/security/ips/7.0/configuration/guide/cli/cli_idsm2.html#wp1030828"&gt;http://www.cisco.com/en/US/customer/docs/security/ips/7.0/configuration/guide/cli/cli_idsm2.html#wp1030828&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Apr 2011 06:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/span-configuration-for-idsm/m-p/1695762#M65309</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2011-04-11T06:32:15Z</dc:date>
    </item>
  </channel>
</rss>

