<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sensing interfaces on IPS! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438021#M67476</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mate,so if i have route from the asa toward the internet router so now route is in place&amp;nbsp; so&amp;nbsp; i need interface pair not vlan pair coz i have route,is that true?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 23 May 2010 14:27:55 GMT</pubDate>
    <dc:creator>alsayed</dc:creator>
    <dc:date>2010-05-23T14:27:55Z</dc:date>
    <item>
      <title>Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438016#M67464</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have IPS 4215 with 6.0 image, 4 sensing Interfaces anlong with the C&amp;amp;C,i m confused a litlte bit about the sensing interfaces across the network what am thinking is as follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS will be functions as inline mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Two sensing interfaces bridged togather on the inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Two sensing interfaces&amp;nbsp; bridged togather on the outside, coz i have&amp;nbsp; web server on the DMZ Need to be accessed from outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but the inline rule said:traffic from interface to onother interface need to be checked , so how is that with traffic leaving my network to the internet so it nee to be checked either wich useless in this case coz i just need inspection to traffic comes from outside toward my web server and inspection the inside interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help here in order to determine the ideal deployment for the sensors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438016#M67464</guid>
      <dc:creator>alsayed</dc:creator>
      <dc:date>2019-03-10T11:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438017#M67465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure VLAN Pair for each of the network segments that you would like to get the IPS inspected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Example&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;1st sensing interface, configure it as a dot1q trunk port:&lt;/P&gt;&lt;P&gt;- Eg: if your inside interface is in vlan 50, you can map it (bridge it) through the IPS to another vlan (eg: vlan 150).&lt;/P&gt;&lt;P&gt;- So on IPS --&amp;gt; vlan 50 pairs with vlan 150&lt;/P&gt;&lt;P&gt;- All inside hosts are assigned to vlan 50, and its default gateway is assigned to vlan 150, hence the traffic will pass through the IPS in bridge/transparent mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can configure the same for DMZ and outside subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 May 2010 09:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438017#M67465</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-10T09:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438018#M67466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please prepare a drawing for yr suggestions in order to use as a sample?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 May 2010 12:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438018#M67466</guid>
      <dc:creator>alsayed</dc:creator>
      <dc:date>2010-05-10T12:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438019#M67468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please find the vlan pairing and trunk for the IPS sensing interface diagram. The example diagram is for inside subnet, and you can replicate the same for DMZ and Outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 May 2010 10:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438019#M67468</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-11T10:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438020#M67471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Freind&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)so I need 3 sensing interface acting as trunk for 1 for inside and 1 for outside and 1 for dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)Why i have 2 different vlan and the same IP Subnet?what is the reason for that?how the inspection work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 May 2010 11:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438020#M67471</guid>
      <dc:creator>alsayed</dc:creator>
      <dc:date>2010-05-11T11:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438021#M67476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mate,so if i have route from the asa toward the internet router so now route is in place&amp;nbsp; so&amp;nbsp; i need interface pair not vlan pair coz i have route,is that true?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 May 2010 14:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438021#M67476</guid>
      <dc:creator>alsayed</dc:creator>
      <dc:date>2010-05-23T14:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438022#M67481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) Correct, but again, it depends on how you physically and logically connect the IPS in your network.&lt;/P&gt;&lt;P&gt;2) For vlan pair scenario, you would need to have 2 vlans bridging the traffic just like transparent firewall for example, so the traffic is forced to go through the IPS. If you only have 1 VLAN, traffic will directly go to its default gateway, hence will not pass through the IPS appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your questions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 May 2010 00:18:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438022#M67481</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-24T00:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438023#M67485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interface pair means you have to use a pair of the IPS interfaces, ie: one connects to the ASA and the other connects to the router, basically to ensure that traffic that needs to be inspected is passing through the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are not limited to use interface pair, you can also use VLAN pair in your ASA to Internet router scenario. Basically the ASA vlan and the router vlan needs to be different with ASA and router in the same subnet, to force traffic through the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Example&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;ASA outside IP is 200.1.1.1 -- vlan 10&lt;/P&gt;&lt;P&gt;Router interface IP is 200.1.1.2 -- vlan 110&lt;/P&gt;&lt;P&gt;IPS - pairing vlan 10 to vlan 110&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 May 2010 01:01:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438023#M67485</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-24T01:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438024#M67489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello freind&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why 2 different vlan while one single subnet,how the logic goes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do u have different IPS deployment including connectivitys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 May 2010 14:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438024#M67489</guid>
      <dc:creator>alsayed</dc:creator>
      <dc:date>2010-05-24T14:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Sensing interfaces on IPS!</title>
      <link>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438025#M67491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't really find a sample config on IPS, however, here is sample config on the concept on &lt;SPAN style="text-decoration: underline;"&gt;transparent &lt;/SPAN&gt;firewall which is exactly what IPS is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Interface pair (on ASA firewall): &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;VLAN pair (FWSM): &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/exampl_f.html#wp1029042"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm40/configuration/guide/exampl_f.html#wp1029042&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For VLAN pair example, just check the diagram, and basically 1 subnet, and vlan pairing basically to force the traffic to go through the firewall/IPS. Since all hosts are on all 1 layer 3 subnet, it will ARP for the ip address, and if the default gateway is on the other side of the IPS/firewall, the traffic is forced to traverse through the appliance to get to its default gateway. Hence forcing the traffic to be inspected by the IPS. Otherwise, there is no other way to force traffic to pass through the IPS as IPS is layer 2 device (sensing interface is L2), not a routed device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 May 2010 13:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sensing-interfaces-on-ips/m-p/1438025#M67491</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-25T13:14:18Z</dc:date>
    </item>
  </channel>
</rss>

