<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VLAN PAIRS Bypass or failover?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454890#M67276</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The sensor knows the vlan tags, so he will change the vlan tags when bridging the vlans.&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Jun 2010 23:58:07 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-06-08T23:58:07Z</dc:date>
    <item>
      <title>VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454885#M67271</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´m implementing INLINE VLAN PAIRS in two 4260 and a 4270.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that the BYPASS is a software failover. But what is going to happen if the hardware fails???? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Who is going to do the VLAN re-tagging???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is going to happen with that traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there are way to configure the switch to re-direct the traffic if the IPS is DOWN. of a way to do the re-tag in the switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would really appreciate your comments and suggestions.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454885#M67271</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2019-03-10T12:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454886#M67272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to perform the failopen function outside the IPS sensor.&lt;/P&gt;&lt;P&gt;Use an external (to the sensor) switch, create two VLANS, connect them together via the sensor (each VALN to sensor connection is a Trunk with one one VLAN in it). Then create a second connection via a patch cable betwen the two VLANS, give it a higher STP metric, enable Spanning tree on these 4 ports. The bypass cable will only run traffic if the sensor stops passing BPDUs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jun 2010 17:00:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454886#M67272</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2010-06-07T17:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454887#M67273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi rhermes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understood the STP part but not the connections part. I´m using only 1 interface to do the VLAN PAIR, the retag is being done in an interface.(and 1 interface in the switch). where should I connect the 4 ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jun 2010 17:28:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454887#M67273</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-06-07T17:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454888#M67274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're only using one interface on the sensor, then you only need three switch ports; one trunking both VLANS to the sensor and one port in each VLAN as a regular (non-trunked) access port connected together via a patch cable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jun 2010 18:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454888#M67274</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2010-06-07T18:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454889#M67275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;last question. Who is going to make the vlan re-tagging? will VLAN 1 be able to talk to VLAN2 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 17:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454889#M67275</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-06-08T17:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454890#M67276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The sensor knows the vlan tags, so he will change the vlan tags when bridging the vlans.&lt;/P&gt;&lt;P&gt;I hope it makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jun 2010 23:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454890#M67276</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-06-08T23:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: VLAN PAIRS Bypass or failover??</title>
      <link>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454891#M67277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When traffic flow through the IPS Sensor, the VLAN pair in the sensor will re-tag the traffic on the trunk port..&lt;/P&gt;&lt;P&gt;When the sensor stops passing layer 2 frames, Spanning trree Protocol will unblock the failover cable port and allow traffic to pass between VLAN 1 and VLAN2 untaged (these poerts are not trunks).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jun 2010 05:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-pairs-bypass-or-failover/m-p/1454891#M67277</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2010-06-09T05:17:28Z</dc:date>
    </item>
  </channel>
</rss>

