<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS VLAN question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555630#M66056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; The packets are not tagged with VLAN information when sent out of the SPAN port so the IDS does not need to be configured with any trunking/VLAN awareness information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Dec 2010 17:34:23 GMT</pubDate>
    <dc:creator>Justin Teixeira</dc:creator>
    <dc:date>2010-12-01T17:34:23Z</dc:date>
    <item>
      <title>IPS VLAN question</title>
      <link>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555627#M66051</link>
      <description>&lt;P&gt;I am configuring an IPS 4260 in promiscious mode, and have a question about VLAN assignment.&amp;nbsp; Does the sensing interface need to be in the same VLAN as the switchport you are spanning?&amp;nbsp; Also does this port need to be a trunk?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also If you want to log traffic only and not issue resets, do you just leave the default or do I need to switch anything off?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555627#M66051</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2019-03-10T12:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPS VLAN question</title>
      <link>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555628#M66052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Networker99,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; As long as you aren't using the "encapsulate replicate" command on the SPAN session sending the traffic to the sensor, the traffic will be copied without VLAN tagging information and no additional configuration on the IDS side should be necessary. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to prevent TCP resets you should either designate an unused port as an alternate TCP reset interface for the promiscuous sensing interface or, alternatively, create a simple Event Action Filter to remove the "TCP Reset" action from all signatures on the sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Justin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 16:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555628#M66052</guid>
      <dc:creator>Justin Teixeira</dc:creator>
      <dc:date>2010-12-01T16:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPS VLAN question</title>
      <link>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555629#M66055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the port being used as a sensor doesnt need to be a trunk, correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 16:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555629#M66055</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-12-01T16:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPS VLAN question</title>
      <link>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555630#M66056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct.&amp;nbsp; The packets are not tagged with VLAN information when sent out of the SPAN port so the IDS does not need to be configured with any trunking/VLAN awareness information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-JT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 17:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-vlan-question/m-p/1555630#M66056</guid>
      <dc:creator>Justin Teixeira</dc:creator>
      <dc:date>2010-12-01T17:34:23Z</dc:date>
    </item>
  </channel>
</rss>

