06-26-2008 11:21 AM - edited 03-11-2019 06:05 AM
I have an ISS IPS that I would like to put inline in front of my FWSM. This should be straight forward, but I want to use transit VLANs instead of physical connections. My question is can this be done? If it can, how would I do it? I have accomplished this same thing with an IPS appliance, but I am not sure if it will work the same with the FWSM.
Thanks.
Jay
06-26-2008 12:09 PM
What do you mean "to use transit VLANs instead of physical connections"?
06-26-2008 12:22 PM
The IPS will work if you create two VLANs and use it as a bridge. Alternatively, you can physically connect the IPS to network devices.
06-26-2008 12:31 PM
what's the problem?
create two vlans and let the IPS to be a bridge beween them.
06-26-2008 12:38 PM
06-26-2008 01:23 PM
If your IPS can work inline So It will do.
You can easily inclide/exclude the IPS from switching path just put your vpn concentrator's inteface in vlan 15 or 10.
06-26-2008 09:52 PM
If your ISS IPS supports Inline Mode, then everything should be fine. As far as the FWSM and VPN concentrator are concerned, adding a layer 2 device does not change much for them.
A properly configured IPS is just a 'transparent' device like a L2 switch.
Regards
Farrukh
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide