<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: General 4215 Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532927#M98534</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. My FE0/0 is my management port and I will be using FE1/0 and FE1/1 for sensing (leaving open FE0/1, FE1/2. amd FE1/3 open for future use). I'd like to inspect traffic for a PIX firewall bound at 100Mbps, so I'm not losing too much in terms of throughput. Would my approach work with the given configuration? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 May 2006 00:24:19 GMT</pubDate>
    <dc:creator>ryanwilhelm</dc:creator>
    <dc:date>2006-05-04T00:24:19Z</dc:date>
    <item>
      <title>General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532922#M98529</link>
      <description>&lt;P&gt;I'm quite a newbie to the IDS 4215 configuration; however, we just received ours in-house and I would like to run through the set-up with some experts prior to an extended test. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question, I have the cables from Fe1/1 and Fe1/2 plugged into two Gigabit ports on our 6509. I have two destination ports (the ports that ultimately connect back to the Fe ports on the 4215) specified on the 6509 and one source port (our PIX router port connected to the 6509). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Given the config info below and the details from above, do I have the cabling correct and will this approach work? &lt;/P&gt;&lt;P&gt;--Config&lt;/P&gt;&lt;P&gt;virtual-sensor vs0 &lt;/P&gt;&lt;P&gt;description default virtual sensor&lt;/P&gt;&lt;P&gt;logical-interface idspair1 &lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service interface&lt;/P&gt;&lt;P&gt;physical-interfaces FastEthernet0/0 &lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;speed 100&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;physical-interfaces FastEthernet0/1 &lt;/P&gt;&lt;P&gt;description sensing interface&lt;/P&gt;&lt;P&gt;admin-state enabled&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;speed 100&lt;/P&gt;&lt;P&gt;alt-tcp-reset-interface none&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;physical-interfaces FastEthernet1/0 &lt;/P&gt;&lt;P&gt;description Sensing Pair - Part 1&lt;/P&gt;&lt;P&gt;admin-state enabled&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;speed 100&lt;/P&gt;&lt;P&gt;alt-tcp-reset-interface interface-name FastEthernet1/2&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;physical-interfaces FastEthernet1/1 &lt;/P&gt;&lt;P&gt;description Sensing Pair - Part 2&lt;/P&gt;&lt;P&gt;admin-state enabled&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;speed 100&lt;/P&gt;&lt;P&gt;alt-tcp-reset-interface interface-name FastEthernet1/3&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;inline-interfaces idspair1 &lt;/P&gt;&lt;P&gt;description Initial Pair&lt;/P&gt;&lt;P&gt;interface1 FastEthernet1/0&lt;/P&gt;&lt;P&gt;interface2 FastEthernet1/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532922#M98529</guid>
      <dc:creator>ryanwilhelm</dc:creator>
      <dc:date>2019-03-10T09:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532923#M98530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ignore the Fe0/1 interface since I just have it established for promiscuous mode monitoring. I would ultimately like to have this device perform in-line IPS functionality. Do I need to somehow return the packets from the "monitor session" commands issued on the 6509? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the anticipated help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 May 2006 02:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532923#M98530</guid>
      <dc:creator>ryanwilhelm</dc:creator>
      <dc:date>2006-05-02T02:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532924#M98531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ryanwihelm:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im sorry but I'm confused with your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to do inline IPS then you must to conect FE0/1 to the pix, and FE0/2 to the shitch. Then all the trafic go through the IPS.&lt;/P&gt;&lt;P&gt;Don't forget to conect FE0/0 to the switch (perhaps in other vlan) for management reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This response help to you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another comment, Do you know the max througput you have with 4215 is 65 Mbps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alberto Giorgi from spain (a new kid in this block)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2006 21:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532924#M98531</guid>
      <dc:creator>a.giorgi</dc:creator>
      <dc:date>2006-05-03T21:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532925#M98532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ryanwihelm:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im sorry but I'm confused with your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to do inline IPS then you must to conect FE0/1 to the pix, and FE0/2 to the shitch. Then all the trafic go through the IPS.&lt;/P&gt;&lt;P&gt;Don't forget to conect FE0/0 to the switch (perhaps in other vlan) for management reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This response help to you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another comment, Do you know the max througput you have with 4215 is 65 Mbps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alberto Giorgi from spain (a new kid in this block)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2006 21:38:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532925#M98532</guid>
      <dc:creator>a.giorgi</dc:creator>
      <dc:date>2006-05-03T21:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532926#M98533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ryanwihelm:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im sorry but I'm confused with your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to do inline IPS then you must to conect FE0/1 to the pix, and FE0/2 to the shitch. Then all the trafic go through the IPS.&lt;/P&gt;&lt;P&gt;Don't forget to connect FE0/0 to the switch (perhaps in other vlan) for management reasons.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This response help to you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another comment, Do you know the max througput you have with 4215 is 65 Mbps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alberto Giorgi from spain (a new kid in this block)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 May 2006 21:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532926#M98533</guid>
      <dc:creator>a.giorgi</dc:creator>
      <dc:date>2006-05-03T21:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532927#M98534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. My FE0/0 is my management port and I will be using FE1/0 and FE1/1 for sensing (leaving open FE0/1, FE1/2. amd FE1/3 open for future use). I'd like to inspect traffic for a PIX firewall bound at 100Mbps, so I'm not losing too much in terms of throughput. Would my approach work with the given configuration? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2006 00:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532927#M98534</guid>
      <dc:creator>ryanwilhelm</dc:creator>
      <dc:date>2006-05-04T00:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: General 4215 Question</title>
      <link>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532928#M98535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ryan:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it will work.&lt;/P&gt;&lt;P&gt;Whith your configuration you will be able to inspect the traffic to and from Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a future I suggest you configure the rest of the interfaces to sense the internal traffic. You can SPAN a couple of port of your switch (e.g. for differents VLANs) and use de IDS in the promiscuous mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this help (please rate it this post and the previous one).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alberto Giorgi from spain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2006 06:32:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/general-4215-question/m-p/532928#M98535</guid>
      <dc:creator>a.giorgi</dc:creator>
      <dc:date>2006-05-04T06:32:16Z</dc:date>
    </item>
  </channel>
</rss>

