We have been using SNORT and now evaluating Cisco IPS sensors. The first question is:
- We have 2 ASA 5510 configured as Active/Active failover and have 2 different data centers. How many IPS do we esentially need?
My guess is 2 - one for each data center. But, then how it will connect to both the firewalls?
Or, we just have it its interface go into a switchport and monitor all the traffic from various vlans into the destination port to which IPS is connected to?
-NG