cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1455
Views
10
Helpful
2
Replies
skc455
Beginner

Hello experts, need some knowledge on firepower applicance deployment modes

We don't want to send all our traffic to IPS hence I was looking for options where I can deploy the same device as IPS for some critical data and IDS for other traffic. Some of my friends say firepower can send tcp resets even when its configured as IDS, is that achievable? My understanding was IDS can not take any action since its passively listening to traffic spanned to it. Can someone shed some light on this to me if there is a way to do this ?

1 ACCEPTED SOLUTION

Accepted Solutions
Marvin Rhoads
VIP Community Legend

IDS indeed is completely passive and will not send resets or otherwise block any flows it it's configured properly. If in doubt you can always just feed the appliance from a span or tap port.

Depending on the appliance and software type you are running, you can mix IPS and IDS inline sets on your appliance.

View solution in original post

2 REPLIES 2
Marvin Rhoads
VIP Community Legend