08-13-2007 12:42 PM - edited 03-10-2019 03:44 AM
I want to put the ISDM "in-line" between my internet edge router and my firewall (FWSM which is in the same chassis as the IDSM). In order to have traffic flow from the internet edge router into the IDSM, then out of the IDSM to the FWSM, I will need to set the IDSM interfaces in the appropriate VLANs. I cannot find the procedure for doing this in the documentation.
08-17-2007 11:34 AM
Hope this helps. We run ECLB with inline vlan pair mode. Heres a link to the manual and a link to my orginally posted question, that I figured out.
08-20-2007 09:07 AM
There is very little real documentation (that I have found) that covers this real well.
What I have found to work, think of it this way. Use two separate VLANs, VLAN 10 and VLAN 11 for example. Use the same IP address range over these two VLANs. Put the router in VLAN 10 and the firewall interface in VLAN 11 (or vice versa).
Then configure the IDSM two utilize the two VLANs as a VLAN pair. The only way those two interfaces can communicate (as they are on separate VLANs) is through the IPS module. The IPS module will bridge the two speparate VLANs with the Virtual Sensor Interface.
If there are hosts in the same VLAN, that will not traverse the IPS, but if the interfaces are in separate VLANS 10 and 11 in this example, they will traverse the IPS or any traffic that traverses this connection.
I hope this helps,
Mike
08-20-2007 09:14 AM
The idea above works in general, but there is a bit of a difference with hybrid vs IOS configurations.
The above post works for hybrid fairly well.
With IOS, there are some intrusion commands (3 or 4 of them) that are pretty self explainitory.
I dont have access to either chassis right now to send you a working Cat config.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide