<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDSM2 inline vlan pair mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975277#M79418</link>
    <description>&lt;P&gt;I am working with the IDSM-2, We have Cisco 6509 with CSM &amp;amp; FWSM, We are planning IDSM-2 in Inline &lt;/P&gt;&lt;P&gt;vlan pair mode and now i want to monitor the traffic which is coming through Outside Interface of the FW cont&lt;/P&gt;&lt;P&gt;that is  vlan160 in inline vlan pair mode ,I created the L2 vlan 161 and paired vlans 160 and 161.&lt;/P&gt;&lt;P&gt;My problem is iam able to sea the traffic on interface 0/8 but there is no alerts on IDSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration i was done is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Router # config t&lt;/P&gt;&lt;P&gt;    Router (conf) #vlan 161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Router (conf) # intrusion-detection module 9 data-port 2 trunk allowed-vlan 160,161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Router (conf) # exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor # conf  t&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf) # service interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int) # physical-interfaces gigabit Ethernet 0/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy) # subinterface-type inline-vlan-pair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl) # subinterface 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl-sub) # vlan 1 160&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl-sub) # vlan 2 161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl-sub) # exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;apply changes : yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 11:12:02 GMT</pubDate>
    <dc:creator>isgphyd12</dc:creator>
    <dc:date>2019-03-10T11:12:02Z</dc:date>
    <item>
      <title>IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975277#M79418</link>
      <description>&lt;P&gt;I am working with the IDSM-2, We have Cisco 6509 with CSM &amp;amp; FWSM, We are planning IDSM-2 in Inline &lt;/P&gt;&lt;P&gt;vlan pair mode and now i want to monitor the traffic which is coming through Outside Interface of the FW cont&lt;/P&gt;&lt;P&gt;that is  vlan160 in inline vlan pair mode ,I created the L2 vlan 161 and paired vlans 160 and 161.&lt;/P&gt;&lt;P&gt;My problem is iam able to sea the traffic on interface 0/8 but there is no alerts on IDSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration i was done is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Router # config t&lt;/P&gt;&lt;P&gt;    Router (conf) #vlan 161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Router (conf) # intrusion-detection module 9 data-port 2 trunk allowed-vlan 160,161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Router (conf) # exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor # conf  t&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf) # service interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int) # physical-interfaces gigabit Ethernet 0/8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy) # subinterface-type inline-vlan-pair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl) # subinterface 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl-sub) # vlan 1 160&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl-sub) # vlan 2 161&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sensor (conf-int-phy-inl-sub) # exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;apply changes : yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975277#M79418</guid>
      <dc:creator>isgphyd12</dc:creator>
      <dc:date>2019-03-10T11:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975278#M79419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use IDM or the CLI to configure IDSM-2 to operate in inline VLAN pair mode. To prepare IDSM-2 for inline VLAN pair mode, you must configure the switch as well as IDSM-2. Configure the switch first, then configure the IDSM-2 interfaces for inline VLAN pair mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jul 2008 15:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975278#M79419</guid>
      <dc:creator>smahbub</dc:creator>
      <dc:date>2008-07-22T15:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975279#M79420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the pair added to the Virtual Sensor?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 00:35:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975279#M79420</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-23T00:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975280#M79421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Farrukh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes ,I was added the pair to virtual sensor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;sridhar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 09:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975280#M79421</guid>
      <dc:creator>isgphyd12</dc:creator>
      <dc:date>2008-07-23T09:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975281#M79422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are you testing the IDS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 18:28:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975281#M79422</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-07-23T18:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975282#M79423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Traffic is going through the VLAN but there is no logs on event viewer.&lt;/P&gt;&lt;P&gt;I need a sample configuration with 6500---IDSM--FWSM. There might be a problem with 6500 configuration.&lt;/P&gt;&lt;P&gt;Valn 160 is Outside interface of FWSM context and there is not traffic on vlan 161 but we are able to access outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jul 2008 05:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975282#M79423</guid>
      <dc:creator>isgphyd12</dc:creator>
      <dc:date>2008-07-24T05:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975283#M79424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem that i do not know how to handle. I have 100 Vlans and I would like to use the IPS to inspect traffi&lt;STRONG&gt;&lt;EM&gt;c &lt;SPAN&gt;&lt;SPAN&gt;between these VLANS. I have 2 questions.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; In a Vlan pair only 2 vlans are paired so the traffic between this VLANS will be inspected. How can I inspect the traffic for example when vlan 15 comunicates with vlan 20, 50, 30, 80 etc...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I know that the comunication between the Switch and the IPS should be through a Trunk port. What else do I have to configure in the L3switch?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would really appreciate the help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Dec 2009 21:05:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975283#M79424</guid>
      <dc:creator>Diego Armando Cambronero Arias</dc:creator>
      <dc:date>2009-12-08T21:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 inline vlan pair mode</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975284#M79425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please open a separate post for this issue. Just select the 'New' button ot the top right of the screen and click on 'Discussion'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to remember that the IPS in not a layer 3 device, its a L2 devices.....so you really don't have to wait for inter-VLAN routing. If the IPS will monitor one VLAN, it will cover ALL communication to/from that VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Dec 2009 06:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-inline-vlan-pair-mode/m-p/975284#M79425</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2009-12-15T06:30:06Z</dc:date>
    </item>
  </channel>
</rss>

