cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
689
Views
0
Helpful
1
Replies

ips failover

mirehteshamali
Level 1
Level 1

hi all

i have recently designed a solution having  firewall failover in active standby mode .

now i need to add ips in inline mode. with failover capability .

1) is their any failover of ips 4210 ? further how many signatures does 4210 supports ..

2) is CSC card a substitue of IPS card on ASA ?

3 )Will CSC ---asa---4210ips --------inside network , slow down due to repeated scanning at various levels ??

thanks

1 Accepted Solution

Accepted Solutions

andrey.dugin
Level 1
Level 1

I'll try to answer.

1) As I know there were no failover features in Cisco IPS.

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/white_paper_c11-459025.html

According to the document IPS has no additional influence on traffic in firewall failover situations but IPS cannot be clustered.

You can configure fail-open hardware bypass feature for IPS to permit traffic through it when IPS fails or use fail-close feature to stop traffic when IPS fails.

2) CSC is not 100% substitute for IPS.

3) It depends on your network.

View solution in original post

1 Reply 1

andrey.dugin
Level 1
Level 1

I'll try to answer.

1) As I know there were no failover features in Cisco IPS.

http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5729/ps5713/ps4077/white_paper_c11-459025.html

According to the document IPS has no additional influence on traffic in firewall failover situations but IPS cannot be clustered.

You can configure fail-open hardware bypass feature for IPS to permit traffic through it when IPS fails or use fail-close feature to stop traffic when IPS fails.

2) CSC is not 100% substitute for IPS.

3) It depends on your network.

Review Cisco Networking for a $25 gift card