cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1696
Views
5
Helpful
1
Replies

FTD as IPS Deployment

fatalXerror
Level 5
Level 5

Hi Guys,

I am deploying a new 4100 as an IPS but when I register it in FMC it shows routed mode. Does it affect the IPS if it run in routed mode? I just want my IPS like a bump in a wire so I decided to configure it with inline pairs.

Does it still check for routing even though my interfaces are inline pairs?

Thanks

1 Accepted Solution

Accepted Solutions

Here you go.


- When you configure an Inline Pair 2 Physical interfaces are internally
bridged
- Very similar to classic inline Intrusion Prevention System (IPS)
- Available in Routed or Transparent Deployment modes
- Most of the LINA engine features (NAT, Routing etc) are not available
for flows which go through an Inline Pair
- Transit traffic can be dropped
- Few LINA engine checks are applied along with full Snort engine checks


Short answer, inline pair will act as IPS and not routing will be taking
place for packets coming on inline interface.

View solution in original post

1 Reply 1

Here you go.


- When you configure an Inline Pair 2 Physical interfaces are internally
bridged
- Very similar to classic inline Intrusion Prevention System (IPS)
- Available in Routed or Transparent Deployment modes
- Most of the LINA engine features (NAT, Routing etc) are not available
for flows which go through an Inline Pair
- Transit traffic can be dropped
- Few LINA engine checks are applied along with full Snort engine checks


Short answer, inline pair will act as IPS and not routing will be taking
place for packets coming on inline interface.
Review Cisco Networking for a $25 gift card