<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM &amp; IDSM2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494183#M804485</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;not a problem.. glad to help you.&amp;nbsp; the scenario that comes to mind is if you were bridging two vlans for whatever reason maybe another external device connected to the 6500 switch.&amp;nbsp; something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan1----IDSM2-----vlan 2-----switch-------externaldevice-----switch----vlan3----IDSM2----vlan4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;everything was bridged.. not sure why you would, but if it were, then the packet would be the same throughout the entire flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the IDSM2, you wont really run into this much, with our external 42xx series IPS devices, you could and because the code is the same base, you would need 2 virtual sensors like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host A-----inline4200IPS----vlan1switch------inline4200IPS---host B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simplified.. of course. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Aug 2010 20:51:05 GMT</pubDate>
    <dc:creator>Scott Nishimura</dc:creator>
    <dc:date>2010-08-20T20:51:05Z</dc:date>
    <item>
      <title>FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494169#M804036</link>
      <description>&lt;P&gt;Dear's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any different configuration for 6500 or IDSM-2 if i m placing with FWSM???? . I will place IDSM-2 in inline vlan pair mode,and all SVI will be created on FWSM instead of MSFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestion please on above design and configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494169#M804036</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2019-03-11T18:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494170#M804042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dears,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nobody has ever been before installed IDSM-2 with FWSM?????&amp;nbsp; Experts i need ur hints before implementing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 20:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494170#M804042</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-17T20:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494171#M804085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have implemented a a similar configuration before, except that my IDSMs were in promiscuous mode using VACLs to capture traffic.&amp;nbsp; Also, my FWSMs were in transparent, multi-context mode.&amp;nbsp; That certainly made things more complicated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, no, there's not really any "special" or different configuration you will need to do.&amp;nbsp; Just remember that you will want to create 2 virtual sensors -- one for the inside network, and one for the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apart from the configuration guides for each module, as well as the 6500 config guide, I would suggest reading through some of Cisco's &lt;A href="http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/SAFE_RG/SAFE_rg.html"&gt;SAFE Reference Guide&lt;/A&gt;.&amp;nbsp; In particular, be sure to read the chapters for &lt;A href="http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/SAFE_RG/chap6.html"&gt;Enterprise Internet Edge&lt;/A&gt; (Ch. 6) and &lt;A href="http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/SAFE_RG/chap7.html"&gt;Enterprise WAN Edge&lt;/A&gt; (Ch. 7).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Aug 2010 23:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494171#M804085</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2010-08-17T23:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494172#M804115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why we need to create 2 virtual sensors 1 for inside and 1 for outside??? Can u explain me??.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 19:18:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494172#M804115</guid>
      <dc:creator>lambay2000</dc:creator>
      <dc:date>2010-08-19T19:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494173#M804142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The use of two virtual sensors would be needed if the same traffic is passing through IDSM twice.&amp;nbsp; If using just 1 virtual sensor and it sees it twice, it would drop it. You would see this using inline and if it was being bridged which would cause the traffic to be identical.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 19:52:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494173#M804142</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-19T19:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494174#M804192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In 1 virtual sensor also traffic is passed 2 times to IDSM-2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example for inline vlan pair mode.if i want to allow inter-vlan routing from vlan 100 to vlan 200.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INLINE VLAN PAIR: vlan 1 and vlan2 are real SVI interface and vlan 100 and vlan 200 are virtual just for pairing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 1 to 100&lt;/P&gt;&lt;P&gt;vlan 2 to 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;USER-PC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SWITCH SVI&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SWITCH SVI&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; USER-PC&lt;/P&gt;&lt;P&gt;vlan 100----IDSM--------int vlan1 SVI --- ----int vlan2 SVI-------IDSM----vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UR help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: estela mathew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 11:41:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494174#M804192</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T11:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494175#M804246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your situation, having the same idsm inspect at two different points of your network with the same virtual sensor should be fine as the key part is that you are intervlan routing it.&amp;nbsp; By doing so, the packet is being altered and therefore the virtual sensor is not seeing an identical packet.&amp;nbsp; We used to see this alot in the past when inline was a new feature and people were using 1 virtual sensor for multiple points and the traffic remaining the same due to bridging.&amp;nbsp; They introduced multiple virtual sensors to get around this later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But with your scenario, you should not run into that problem because you are intervlan routing between the two segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 17:24:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494175#M804246</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T17:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494176#M804281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your situation, having the same idsm inspect at two different points&amp;nbsp; of your network with the same virtual sensor should be fine as the key&amp;nbsp; part is that you are intervlan routing it.&amp;nbsp; By doing so, the packet is&amp;nbsp; being altered and therefore the virtual sensor is not seeing an&amp;nbsp; identical packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did'nt understood ur reply?? The packet is being altered where ????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explore more the traffic flow for normal&amp;nbsp; Intervlan routing without a FWSM and second option if i place a FWSM and my users vlan wants to access servers in DMZ vlan how the traffic flow will be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope very less Engineers in community has implemented IDSM-2 with FWSM,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Awaiting ur reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 19:08:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494176#M804281</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T19:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494177#M804306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you are intervlan routing the traffic, the packet's mac addresses are altered and it ttl gets decremented, etc..&amp;nbsp; these changes are seen by your IDSM virtual sensor so it treats it as new versus seeing the exact same packet -- same mac addresses, etc if it was bridged. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The intervlan routing is the key part here to preventing the virtual sensor from seeing the same packet twice when you are setting inline on both sides.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the perspective of the IDSM, it doesnt care whether its being intervlan routed by the switch or if the fwsm is handling the routing for those vlans.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;That is probably the reason why you dont read much about this as it doesnt really know about the fwsm in the switch.&amp;nbsp; Are you running into a problem when you have both operating at the same time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 19:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494177#M804306</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T19:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494178#M804354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please read the thread below of&amp;nbsp; MARCABAL he is also explaining to create 2 virtual sensors if FWSM is in place,but still i m not clear with the traffic flow if IDSM and FWSM&amp;nbsp; together installed in 1 switch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/thread/245833"&gt;https://supportforums.cisco.com/thread/245833&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By reading the above thread if u can help me to explore the traffic. For example if users vlan want to access DMZ Server vlan if FWSM is in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:Are you running into a problem when you have both operating at the same&amp;nbsp; time?&lt;/P&gt;&lt;P&gt;Answer: Upcoming project may be next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 19:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494178#M804354</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T19:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494179#M804384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not really seeing any problem with the description of the other link.&amp;nbsp; Running with multiple virtual sensors is fine.&amp;nbsp; I was just answering your question on the reasoning behind why you need to run multiple virtual sensors.&amp;nbsp;&amp;nbsp;&amp;nbsp; Since the fwsm is handling the routing, the traffic will be routed by the fwsm.&amp;nbsp; Since the IDSM is only inspecting the traffic, the inline can be put anywhere.&amp;nbsp; Usually people monitor the inside and outside.&amp;nbsp; The firewall doesnt care about the IDSM monitoring the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host a sends traffic on vlan 1 which is bridged by the IDSM doing inline to vlan 2.&amp;nbsp; Vlan 2 is then intervlan routed to vlan 3 which is bridged by the same IDSM doing inline to vlan 4 where the server is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would be the path of the traffic flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 20:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494179#M804384</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T20:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494180#M804408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:I was just answering your question on the reasoning behind why you need&amp;nbsp; to run multiple virtual sensors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer: Uptil now I was thinking of only 1 virtual sensor but Michael Crowe in the above thread he wrote to use 2 virtual sensor 1 for inside and 1 for outside,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explore when we need 2 virtual sensor when inside and outside traffic is to be monitored. As usual the traffic what i was going to monitor from user vlan to&amp;nbsp; server -DMZ vlan the same i will monitor for outside vlan then why michael post that we should have 2 virtual sensor for inside and outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From ur above reply can u answer the below question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:We used to see this alot in the past when inline was a new feature&amp;nbsp; and people were using 1 virtual sensor for multiple points and the&amp;nbsp; traffic remaining the same due to bridging.&amp;nbsp; They introduced multiple&amp;nbsp; virtual sensors to get around this later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 20:29:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494180#M804408</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T20:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494181#M804449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant really comment on the design however, since you are using intervlan routing between the two inlines, you can get away with running one virtual sensor.&amp;nbsp; You may use two virtual sensors if you want.. again, that is the reasoning for the multiple virtual sensors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have up to 4 virtual sensors, you can use two of them for this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 20:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494181#M804449</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T20:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494182#M804467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate ur replies and being with me to help , just need to be clear for each and every point rather being a Parrot engineer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From ur above reply can u answer the below question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question:We&amp;nbsp; used to see this alot in the past when inline was a new feature&amp;nbsp; and&amp;nbsp; people were using 1 virtual sensor for multiple points and the&amp;nbsp; traffic&amp;nbsp; remaining the same due to bridging.&amp;nbsp; They introduced multiple&amp;nbsp; virtual&amp;nbsp; sensors to get around this later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answer ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tell me any scenario with traffic flow explanation says that we need 2 virtual sensors&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 20:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494182#M804467</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T20:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494183#M804485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;not a problem.. glad to help you.&amp;nbsp; the scenario that comes to mind is if you were bridging two vlans for whatever reason maybe another external device connected to the 6500 switch.&amp;nbsp; something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan1----IDSM2-----vlan 2-----switch-------externaldevice-----switch----vlan3----IDSM2----vlan4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;everything was bridged.. not sure why you would, but if it were, then the packet would be the same throughout the entire flow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the IDSM2, you wont really run into this much, with our external 42xx series IPS devices, you could and because the code is the same base, you would need 2 virtual sensors like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host A-----inline4200IPS----vlan1switch------inline4200IPS---host B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simplified.. of course. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 20:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494183#M804485</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T20:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494184#M804500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you would need 2 virtual sensors like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host&amp;nbsp; A-----inline4200IPS----vlan1switch------inline4200IPS---host B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Really i did'nt understood the above diagram,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If suppose i dont have a IDSM-2 and i have a 4200 series&amp;nbsp; IPS still the traffic flow is same as such it was for IDSM-2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pairing:real SVI created for vlan 2 and 3 and dummy vlan 1 and 4&lt;/P&gt;&lt;P&gt;vlan 1 to 2&lt;/P&gt;&lt;P&gt;vlan 3 to 4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan4&lt;/P&gt;&lt;P&gt;hostA--- 4200----int vlan2--------int vlan 3------4200----hostB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above diagram is for 1 virtual sensor&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 21:26:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494184#M804500</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T21:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494185#M804525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, that is correct.. not much difference, except in your diagram, you would be also bridging vlan 2 to vlan 3 keeping it L2 the entire way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 21:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494185#M804525</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T21:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494186#M804535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vlan 2 and vlan 3 are already bridging by 1 and 4.&amp;nbsp;&amp;nbsp; 1 and 4 are dummy vlan only for bridging purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i made a mistake is typing in above mail pairing option&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explain me the below lines&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the IDSM2, you wont really run into this much, with our external&amp;nbsp; 42xx series IPS devices, you could and because the code is the same&amp;nbsp; base, you would need 2 virtual sensors like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host&amp;nbsp; A-----inline4200IPS----vlan1switch------inline4200IPS---host B&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 21:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494186#M804535</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T21:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494187#M804542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes, thats correct..&amp;nbsp; if vlan 2 and 3 were also bridged, then it would be L2 straight through from both end points. &lt;/P&gt;&lt;P&gt;As mentioned earlier, its not as prevalent nowadays.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 21:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494187#M804542</guid>
      <dc:creator>Scott Nishimura</dc:creator>
      <dc:date>2010-08-20T21:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM &amp; IDSM2</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494188#M804549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank u very much Scott for ur replies,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will continue tomorrow as it is 2:00 midnight here,and also 1 task assigned in weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks see u tomorrow i will review the thread again and see it gets more clear or not,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanking once more for being with me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 21:47:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-idsm2/m-p/1494188#M804549</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-08-20T21:47:40Z</dc:date>
    </item>
  </channel>
</rss>

