<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS-BYPASS Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374858#M68015</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 4260 and 4270 both uses the 4GE card. This card does have a hardware bypass feature. In the event of a power failure the two GigE interfaces are physically connected together:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/7.0/installation/guide/hw_installing_4270.html#wp67704"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/installation/guide/hw_installing_4270.html#wp67704&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you mentioned that you were doing a VLAN pair, this will not work with a hardware failopen feature (such as the one found in the 4GE card).&lt;/P&gt;&lt;P&gt;You are arriving at the IPS sensor on one VLAN and leaving the IPS Sensor on a different VLAN (on the same interface? on different interfaces?) When the IPS sensor is functioning normally, it will translate the VLAN header between the two directions of traffic. A hardware failopen will NOT translate VLAN headers.&lt;/P&gt;&lt;P&gt;If you want to contunie to use VLAN pairs, you will need to perfrom your fail over functionality in an external device, such as a switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Feb 2010 17:31:44 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2010-02-12T17:31:44Z</dc:date>
    <item>
      <title>IPS-BYPASS Question</title>
      <link>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374857#M68011</link>
      <description>&lt;P&gt;Hello experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working with 2 4260 and a 4270, I will be implementing vlan pair and I would like to know what happens with the traffic if for any reason the IPS fails. Lets say that the failure is due to a power issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374857#M68011</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2019-03-10T11:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPS-BYPASS Question</title>
      <link>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374858#M68015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The 4260 and 4270 both uses the 4GE card. This card does have a hardware bypass feature. In the event of a power failure the two GigE interfaces are physically connected together:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ips/7.0/installation/guide/hw_installing_4270.html#wp67704"&gt;http://www.cisco.com/en/US/docs/security/ips/7.0/installation/guide/hw_installing_4270.html#wp67704&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you mentioned that you were doing a VLAN pair, this will not work with a hardware failopen feature (such as the one found in the 4GE card).&lt;/P&gt;&lt;P&gt;You are arriving at the IPS sensor on one VLAN and leaving the IPS Sensor on a different VLAN (on the same interface? on different interfaces?) When the IPS sensor is functioning normally, it will translate the VLAN header between the two directions of traffic. A hardware failopen will NOT translate VLAN headers.&lt;/P&gt;&lt;P&gt;If you want to contunie to use VLAN pairs, you will need to perfrom your fail over functionality in an external device, such as a switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2010 17:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374858#M68015</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2010-02-12T17:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: IPS-BYPASS Question</title>
      <link>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374859#M68017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I,m doing it in the same interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that the best option is to route the traffic from the switch in order to do NOT send the traffic to the IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually the IPS are doing a "VLAN Mapping" so when it receives the traffic on vlan 310 for example it forwards the traffic on VLAN 311 it does a re-tag of the vlan tag.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to configure the VLAN Map in the switches?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2010 20:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374859#M68017</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2010-02-12T20:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPS-BYPASS Question</title>
      <link>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374860#M68020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. You want to create a stand by path between VLAN 310 and 311 in the switch.&lt;/P&gt;&lt;P&gt;Add an additional interface to each VLAN on the switch, cable them together with an ethernet patch cable.&lt;/P&gt;&lt;P&gt;Turn on Spanning Tree Protocol on VLAN 310 and 311 and set the "fail-over" path thru your patch cable to a higher STP cost.&lt;/P&gt;&lt;P&gt;Once the STP BTDU's fail to pass thru the IPS sensor, the stand by path thru the fail over cable will be enabled.&lt;/P&gt;&lt;P&gt;You'll have to play with the timing options to get it to happen in less than the standard STP of 15 seconds or so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2010 22:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-bypass-question/m-p/1374860#M68020</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2010-02-12T22:16:06Z</dc:date>
    </item>
  </channel>
</rss>

