cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
807
Views
5
Helpful
3
Replies

IDS 4215 Placement

raventura
Level 1
Level 1

Hello everybody, my problem is really simple, I don't know with a Router 2620 and a Firewall 515E how to plug my IDS, Do I need another switch between the Router and Firewall for this to work, is that the best way, please help.

3 Replies 3

sachinraja
Level 9
Level 9

Hello,

Are you having a cross cable between ur router and PIX as of now ?? if so, its better to put a switch on the middle, and plug your IDS there...

IDS is always placed at the traffic entering point. You will get maximum information, if you put it between the router and PIX.

Do the following:

1) the IDS sniffing interface should be put in a VLAN aalong with the router ethernet and PIX outside interfaces.

2) mirror the router's port onto the IDS port, by monitor session command.

monitor session 1 source interface fastethernet0/1 (router ethernet)

monitor session 1 destination interface fastethernet0/3 (IDS)

this is the best way of doing it.. let me know if you have any more queries..

Raj

Thank You so much.

Hi ,

can you please mark the case as solved, so that it might be help for others ? rate replies if found useful.

Raj

Review Cisco Networking for a $25 gift card