cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1160
Views
0
Helpful
6
Replies

FWSM and Inline IPS Question

jwalker
Level 3
Level 3

I have an ISS IPS that I would like to put inline in front of my FWSM. This should be straight forward, but I want to use transit VLANs instead of physical connections. My question is can this be done? If it can, how would I do it? I have accomplished this same thing with an IPS appliance, but I am not sure if it will work the same with the FWSM.

Thanks.

Jay

6 Replies 6

a.alekseev
Level 7
Level 7

What do you mean "to use transit VLANs instead of physical connections"?

The IPS will work if you create two VLANs and use it as a bridge. Alternatively, you can physically connect the IPS to network devices.

what's the problem?

create two vlans and let the IPS to be a bridge beween them.

Here is a sketch of what I'm trying to do... I just want to know if it will work?

Thanks.

Jay

If your IPS can work inline So It will do.

You can easily inclide/exclude the IPS from switching path just put your vpn concentrator's inteface in vlan 15 or 10.

If your ISS IPS supports Inline Mode, then everything should be fine. As far as the FWSM and VPN concentrator are concerned, adding a layer 2 device does not change much for them.

A properly configured IPS is just a 'transparent' device like a L2 switch.

Regards

Farrukh

Review Cisco Networking for a $25 gift card