cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1559
Views
10
Helpful
2
Replies

Hello experts, need some knowledge on firepower applicance deployment modes

skc455
Level 1
Level 1

We don't want to send all our traffic to IPS hence I was looking for options where I can deploy the same device as IPS for some critical data and IDS for other traffic. Some of my friends say firepower can send tcp resets even when its configured as IDS, is that achievable? My understanding was IDS can not take any action since its passively listening to traffic spanned to it. Can someone shed some light on this to me if there is a way to do this ?

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

IDS indeed is completely passive and will not send resets or otherwise block any flows it it's configured properly. If in doubt you can always just feed the appliance from a span or tap port.

Depending on the appliance and software type you are running, you can mix IPS and IDS inline sets on your appliance.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

IDS indeed is completely passive and will not send resets or otherwise block any flows it it's configured properly. If in doubt you can always just feed the appliance from a span or tap port.

Depending on the appliance and software type you are running, you can mix IPS and IDS inline sets on your appliance.

Thank you for confirming Marvin

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card