<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDSM2 and FWSM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831212#M84652</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One solution might also be to SPAN monitor the port channel serving the FWSM. In my case it's po 271. If you filter the SPAN session on only vlan 60 you should get the traffic flowing in and out of the FWSM outside interface towards the MSFC.&lt;/P&gt;&lt;P&gt;I've tried this a few times with a sniffer and it seems to work. Haven't tried it with the IDSM though&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Feb 2008 09:54:09 GMT</pubDate>
    <dc:creator>hoffa2000</dc:creator>
    <dc:date>2008-02-20T09:54:09Z</dc:date>
    <item>
      <title>IDSM2 and FWSM</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831210#M84650</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have question regarding IDSM2 implementation in FWSM environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN 60 is outside interface on FWSM&lt;/P&gt;&lt;P&gt;interface Vlan60&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.10.60.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, on Cisco 6500, I have VLAN 60&lt;/P&gt;&lt;P&gt;interface Vlan60&lt;/P&gt;&lt;P&gt; ip address 10.10.60.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything is OK, inside interface on FWSM is SVI 66, everything is UP and FWSM is wporking correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I want to put IDSM2 to monitor ALL traffic between FWSM outside interface and MSFC(6500). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible? And how?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that I need to put some additional VLAN to bridge through IDMS2, creating interface vlan pair (subinterface on data ports of IDSM2), but in thaht case, I am losing connection between FWSM and MSFC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help. Thank You&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831210#M84650</guid>
      <dc:creator>binelipetrov</dc:creator>
      <dc:date>2019-03-10T10:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 and FWSM</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831211#M84651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will need to create a new vlan and then put all traffic between FWSM and MSFC in this vlan. You can also create multiple vlans if required. Then put the vlan for monitoring in the IDSM2. Following link may help you&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/cliIdsm2.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/ips/5.0/configuration/guide/cli/cliIdsm2.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2008 15:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831211#M84651</guid>
      <dc:creator>amritpatek</dc:creator>
      <dc:date>2008-02-18T15:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 and FWSM</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831212#M84652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One solution might also be to SPAN monitor the port channel serving the FWSM. In my case it's po 271. If you filter the SPAN session on only vlan 60 you should get the traffic flowing in and out of the FWSM outside interface towards the MSFC.&lt;/P&gt;&lt;P&gt;I've tried this a few times with a sniffer and it seems to work. Haven't tried it with the IDSM though&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2008 09:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831212#M84652</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2008-02-20T09:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: IDSM2 and FWSM</title>
      <link>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831213#M84653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you have already solved your problem. have you tried changing the inline TCP tracking mode?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 08:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm2-and-fwsm/m-p/831213#M84653</guid>
      <dc:creator>jonix.niebla</dc:creator>
      <dc:date>2008-06-02T08:05:05Z</dc:date>
    </item>
  </channel>
</rss>

