cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
596
Views
0
Helpful
1
Replies

Exclude network traffic from inspection

teperjesi
Level 1
Level 1

Hi,

May I configure my IPS (this is an appliance), not to monitor, analyse some network traffic? I know I can create filters for events, but I want to prevent my box from oversubscribtion, so I don't want to monitor some type of traffic with it.

Thx

1 Reply 1

a.kiprawih
Level 7
Level 7

What kind if traffic you would like to exclude? By not using IPS filter (prevent oversubscribtion or cpu processing), you basically need filter it out at switch/router/firewall port level.

You can create ACL to filter the unwanted traffic from hitting your IPS interface. But the setback is, you might filter passing through traffic/protocol that is needed by clients/hosts on the other side of the network.

I guess this is where you really need the IPS filter. Basically, your IPS model selection should be suitable for the link & bandwidth that it need to monitor/filter to prevent oversubscription.

Rgds,

AK

Review Cisco Networking for a $25 gift card