cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
661
Views
0
Helpful
5
Replies

IDSM-2 IPS (5.x) / Cat IOS questions

jayrademan
Level 1
Level 1

Is my understanding correct that a Catalyst 6500 running Cat IOS supports only Promiscious mode and that Cat IOS does not support IDSM-2 (5.x) Inline mode?

Are there any plans to incorporate Inline Mode (5.x) under Cat IOS in the future, or am I missing something here?

5 Replies 5

gfullage
Cisco Employee
Cisco Employee

An upcoming version of CatIOS code will definately support inline mode.

The IPS 5.0 code, as you're aware, was the first version of IDS code to support inline mode. With the standalone sensors, running it inline requires a physical cabling change. With the IDSM-2 in particular though, you need to be able to configure the Cat-IOS code to push traffic through the device in inline mode.

Unfortunately getting new versions of CatIOS code out the door is not that easy, since there are about 10,000 other features (not just IPS) in the code that are also wanting to be updated, plus other new features, plus all the testing and re-testing that needs to go on before a release. Supporting inline IPS is just one of many major features scheduled for the switch software.

The Release Notes for IPS 5.0 code do say the following:

IDSM-2 only supports inline mode for Catalyst Software 8.4.4(1) with Supervisor Engine 1a, Supervisor Engine 2, Supervisor Engine 32, and Supervisor Engine 720. Inline support for Cisco IOS will be added at a later date.

With the recent release of 12.2(18)SXE last week, Native IOS on the Cat 6K does now support InLine on the IDSM-2.

However, with this initial version the IDSM-2 inline is only supported by the Sup720.

Additional supervisors will be added in later IOS releases.

The User's Guide has been updated with information on how to configure the IDSM-2 for Inline in IOS:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/cliidsm2.htm#wp1044777

Does the Sup2/MSFC2 with native IOS will support inline mode?If I upgrade the Sup2 to 12.2(18)SXE version,can it support inline mode?Thanks your answer a lot.

Not at this time.

The Release Notes for 12.2(18)SXE state:

Supervisor Engine 2 (not supported in Release 12.2(18)SXE and Rebuilds)

http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/122sx/ol_4164.htm#wp1110212

The Sup2 can not be upgraded to 12.2(18)SXE because there is not a 12.2(18)SXE image for the Sup2.

This happens quite often where new features are first tested and released on a single Supervisor platform (the Sup720 in this case).

The features are later tested and released on additional Supervisor platforms in a later Native IOS release.

I am not aware of when a follow on Native IOS version will be released and when/if it will contain Sup2 images in order to support Sup2 and IDSM-2 inline.

You will need to contact your Cisco Sales Representative for the schedule and supervisor platform support of future Native IOS versions.

Marcabal thanks a lot.Maybe I can wait some days to observe the new future native IOS for Sup2.

Review Cisco Networking for a $25 gift card