<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Deployment in a Dual Core Environment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766982#M86620</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right.... I guess I should back up and provide more information about what I am trying to do. So, I have a 4215 without the 4FE optional 4 port NIC that I want to monitor off of two 3750 routing switches. Would you recommend purchasing the card or spanning all Vlans? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 May 2007 14:45:56 GMT</pubDate>
    <dc:creator>cschweigert</dc:creator>
    <dc:date>2007-05-25T14:45:56Z</dc:date>
    <item>
      <title>IPS Deployment in a Dual Core Environment</title>
      <link>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766980#M86616</link>
      <description>&lt;P&gt;Can any one share ideas/recommendations about deploying a Cisco 4215 IPS in an environment that has dual core switchs?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766980#M86616</guid>
      <dc:creator>cschweigert</dc:creator>
      <dc:date>2019-03-10T10:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Deployment in a Dual Core Environment</title>
      <link>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766981#M86618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;look into vacl's and aggregators.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2007 13:39:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766981#M86618</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-05-23T13:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Deployment in a Dual Core Environment</title>
      <link>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766982#M86620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right.... I guess I should back up and provide more information about what I am trying to do. So, I have a 4215 without the 4FE optional 4 port NIC that I want to monitor off of two 3750 routing switches. Would you recommend purchasing the card or spanning all Vlans? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2007 14:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766982#M86620</guid>
      <dc:creator>cschweigert</dc:creator>
      <dc:date>2007-05-25T14:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Deployment in a Dual Core Environment</title>
      <link>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766983#M86622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In 4215 you would have two interfaces, so that would mean you could have one inline pair. I am sure your two core switch traffic has to route through a fw before reaching the internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need not do a promiscous monitoring, create a pair and place the IPS in between the active PIX and switch. This way whenever we have a active PIX, IPS inspects the traffic flows through it. Now in case of either device failing the secondary path can be used for the traffic to still continue passing. This way the traffic is not inspected but its going to be a rare occurence that your PIX would fail that easily or IPS has a hardware failure. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if you can order the 4FE ports seperately contact your partner or Cisco for this information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Hoogen&lt;/P&gt;&lt;P&gt;Do rate if this post helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 May 2007 08:40:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766983#M86622</guid>
      <dc:creator>hoogen_82</dc:creator>
      <dc:date>2007-05-26T08:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Deployment in a Dual Core Environment</title>
      <link>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766984#M86624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume your goal is to monitor all traffic on both switches? If you're not going to purchase the card, you're going to have to get all the traffic down into a single port (the 4215 only has one monitoring port). You might be able to do that without additional equipment using RSPAN. There are numerous other ways to get the 2 feeds down to "one" (hub, additional switch with SPAN, port aggregator).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you get the card, you should be able to use a normal SPAN or VACL on each switch and use a separate physical interface on the sensor.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2007 12:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-deployment-in-a-dual-core-environment/m-p/766984#M86624</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2007-05-29T12:14:28Z</dc:date>
    </item>
  </channel>
</rss>

