cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
914
Views
0
Helpful
2
Replies

Changing IPS from promiscous mode to Inline mode

smetieh001
Level 1
Level 1

Hi Experts,

We are changing our IPS (aip-ssm10) mode of operation from promiscous to Inline mode. Is there any caveats or anything i need to take into consideration before doing the switch? Is there a possibility to roll back incase something doesn't go the way we planned?

I look forward to your responses.

2 Replies 2

changing from promiscous to inline and back is done with the ips-command in the ASA MPF-config. So if you run into problems you can easily switch back.

What you should do before changing to inline:
- check your alerts for false positives and eliminate them first.
- if you can't eliminate all, make sure that the risk-rating doesn't exeed the threshold for the automatic deny-action if configured.
- and of course keep monitoring your events after the switch to inline.


Sent from Cisco Technical Support iPad App

Thanks Karsten.

Review Cisco Networking for a $25 gift card