cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
480
Views
0
Helpful
3
Replies

Fail over of IPS

asfar.zaidi
Level 1
Level 1

Hi Guys

I have Active/Stand by ASA Firewalls and I want to place 2 IPS between my 2 6500 Core Switches and ASA Firewalls for the Internet Traffic.

Can anyone propose any solution for a complete failove of IPS.

Regards/Asfar

3 Replies 3

mdreelan
Level 1
Level 1

Why not put both IPS inline? --for example-- put the active "inside" and "dmz" interfaces from ASA-ACTIVE through IPS#1 and the same for ASA-Standby - put this one's "inside" and "dmz" through IPS#2. If you put the IPS on the outside interface you risk having no visibility on all encrypted traffic.

hi mdreelan ,can you give me a diagram about how to connect?

best regard

Something like this.

Review Cisco Networking for a $25 gift card