<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS 4240 fail open in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609931#M65651</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeniffer,&lt;/P&gt;&lt;P&gt;Thanks for your prompt response. Do you mean to say that if i put the IPS in inline mode &amp;amp; having a single unit, i do have a option of passing traffic if the unit itself goes down?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pratik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Feb 2011 08:33:26 GMT</pubDate>
    <dc:creator>pratik_193</dc:creator>
    <dc:date>2011-02-14T08:33:26Z</dc:date>
    <item>
      <title>IPS 4240 fail open</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609929#M65647</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a single unit of IPS 4240. I want to know if my sensor or the unit itself fails/shutdowns, is there any option where in my traffic will be passed so that there is no downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pratik&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609929#M65647</guid>
      <dc:creator>pratik_193</dc:creator>
      <dc:date>2019-03-10T12:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 fail open</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609930#M65649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure the sensor when it's inline mode with inline-bypass mode "auto" so when the unit fails, it will just pass through the traffic without inspecting it, however, if the sensor is completely shutdown, then no, traffic will be dropped when it's in inline mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is more information on inline bypass mode:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_interfaces.html#wp1047079"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_interfaces.html#wp1047079&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if it's in promiscious mode, then you don't have to worry about it as the packet is not inline and will not cause interruption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 07:55:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609930#M65649</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-14T07:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 fail open</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609931#M65651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jeniffer,&lt;/P&gt;&lt;P&gt;Thanks for your prompt response. Do you mean to say that if i put the IPS in inline mode &amp;amp; having a single unit, i do have a option of passing traffic if the unit itself goes down?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Pratik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 08:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609931#M65651</guid>
      <dc:creator>pratik_193</dc:creator>
      <dc:date>2011-02-14T08:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 fail open</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609932#M65653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the unit is dead, the answer is NO, you can't pass traffic. However, if the unit fails due to its inspection engine not working, then yes, you can pass traffic&lt;/P&gt;&lt;P&gt; like passing traffic through wire (via the IPS).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 08:39:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609932#M65653</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-14T08:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPS 4240 fail open</title>
      <link>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609933#M65655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The sensor has to partially fail in order for it's failopen to work (it has to be sane enough to realize the sensor app has crashed then inact the failopen routine). To protect yourself form the inevitable sensor crash, hardware failure, reboot after update I would suggest you obtain an external FailOpen switch, or make one from an existing switch you have. &lt;BR /&gt;STP can be use to fail around a downed sensor nicely.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Feb 2011 19:51:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-4240-fail-open/m-p/1609933#M65655</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-02-14T19:51:25Z</dc:date>
    </item>
  </channel>
</rss>

