09-22-2020 09:53 AM
We don't want to send all our traffic to IPS hence I was looking for options where I can deploy the same device as IPS for some critical data and IDS for other traffic. Some of my friends say firepower can send tcp resets even when its configured as IDS, is that achievable? My understanding was IDS can not take any action since its passively listening to traffic spanned to it. Can someone shed some light on this to me if there is a way to do this ?
Solved! Go to Solution.
09-22-2020 10:14 AM
IDS indeed is completely passive and will not send resets or otherwise block any flows it it's configured properly. If in doubt you can always just feed the appliance from a span or tap port.
Depending on the appliance and software type you are running, you can mix IPS and IDS inline sets on your appliance.
09-22-2020 10:14 AM
IDS indeed is completely passive and will not send resets or otherwise block any flows it it's configured properly. If in doubt you can always just feed the appliance from a span or tap port.
Depending on the appliance and software type you are running, you can mix IPS and IDS inline sets on your appliance.
09-22-2020 11:36 AM
Thank you for confirming Marvin
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: