<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Design Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086648#M78455</link>
    <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;There are two ASA with failover and  two switches, one internal switch and one DMZ switch. Both ASAs connected to two switches. Now we want to implement IPS here. we are using 4240 model. I want to use two inline interface pairs one for DMZ and one for internal. But the problem is there two ASA. If you show me high level design and how connect ASA to IPS then to switch, that would be very appreciated. &lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Al&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:21:17 GMT</pubDate>
    <dc:creator>alex goshtaei</dc:creator>
    <dc:date>2019-03-10T11:21:17Z</dc:date>
    <item>
      <title>IPS Design Help</title>
      <link>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086648#M78455</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;There are two ASA with failover and  two switches, one internal switch and one DMZ switch. Both ASAs connected to two switches. Now we want to implement IPS here. we are using 4240 model. I want to use two inline interface pairs one for DMZ and one for internal. But the problem is there two ASA. If you show me high level design and how connect ASA to IPS then to switch, that would be very appreciated. &lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Al&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086648#M78455</guid>
      <dc:creator>alex goshtaei</dc:creator>
      <dc:date>2019-03-10T11:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Design Help</title>
      <link>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086649#M78460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Al -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;use the switches to create seperate VLANS for IPS-Internal-inside&lt;/P&gt;&lt;P&gt;IPS-Internal-outside&lt;/P&gt;&lt;P&gt;IPS-DMZ-inside&lt;/P&gt;&lt;P&gt;IPS-DMZ-outside&lt;/P&gt;&lt;P&gt;Make the connections between the inside and outside VLANS thru the 4240.&lt;/P&gt;&lt;P&gt;Add a second eithernet cable between the inside and outside and give it a higher STP cost for failover.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Oct 2008 21:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086649#M78460</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-10-31T21:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Design Help</title>
      <link>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086650#M78466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THanks for your reply, &lt;/P&gt;&lt;P&gt;ASA has three interfaces, one is outside, one is inside and the other one is DMZ. inside and DMZ interfaces are trunk ports with bunch of VLANs each and they are connected to two switches with trunk ports. these two switches are not connected to each other and they are connected to seperate network. &lt;/P&gt;&lt;P&gt;sorry for incomplete description. any suggestion would be very apprecited. &lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Oct 2008 21:40:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-design-help/m-p/1086650#M78466</guid>
      <dc:creator>alex goshtaei</dc:creator>
      <dc:date>2008-10-31T21:40:13Z</dc:date>
    </item>
  </channel>
</rss>

