10-30-2015 03:23 PM - edited 03-12-2019 05:48 AM
I have 2 cisco 5525-x with firepower and the IPS license, I have configured the FireSight and the firewall, everything is working properly but i want to activate the IPS on it, since i have a lot of servers on my DMZ zone which thoses server are accesible from the inside and some of them also from the outside.
My question is if I activated the IPS would be any traffic block?, would it takes my network down? what are the risk if I enable the IPS?
Thank you all in advance.
Here is my network scheme in simple way..
11-01-2015 08:24 PM
IPS will act based on signatures, by default enabling it should not drop or impact the existing traffic. (unless legitamate harmful traffic)
You can configure it first on passive TAP mode. In this mode the IPS will not drop any traffic instead only a copy of packet is sent to IPS to monitor the traffic.
11-02-2015 11:31 AM
Thanks, I will do that for testing,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide