cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1322
Views
0
Helpful
2
Replies

Cisco ASA 5525-X with FirePower and IPS license

sistematico
Level 1
Level 1

I have 2 cisco 5525-x with firepower and the IPS license, I have configured the FireSight and the firewall, everything is working properly but i want to activate the IPS on it, since i have a lot of servers on my DMZ zone which thoses server are accesible from the inside and some of them also from the outside.

My question is if I activated the IPS would be any traffic block?, would it takes my network down? what are the risk if I enable the IPS?

Thank you all in advance.

Here is my network scheme in simple way.. 

2 Replies 2

prasmura
Cisco Employee
Cisco Employee

IPS will act based on signatures, by default enabling it should not drop or impact the existing traffic. (unless legitamate harmful traffic)

You can configure it first on passive TAP mode. In this mode the IPS will not drop any traffic instead only a copy of packet is sent to IPS to monitor the traffic.

Thanks, I will do that for testing,

Review Cisco Networking for a $25 gift card