cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
340
Views
0
Helpful
2
Replies

IPS on IOS

NAVIN PARWAL
Level 2
Level 2

Folks,

Please correct me if i am wrong. If i configure IPS on my 7200 series router (Internet router),using CLI into copy the drop.sdf file with the built in signatures and then applying the IPS inbound to the DS-3 interface, I will not drop packets even if the signatures are matched by default, unless i go to SDM and configure to do so???

I just do not want any unexpected interruption on my internet router when i configure the IPS feature on my internet router.

Thanks,

2 Replies 2

pradeepde
Level 5
Level 5

The default behavior for engine failure allows for packets to be passed unscanned. To prevent traffic from being passed unscanned, issue the "ip ips fail closed" command, which forces the router to drop all packets if an SME build fails.

thanks for the reponse.

My question was that can i apply IPS statement in multiple Vlans at the same time in a sup 720 Running in hyrid mode??

Thanks

Review Cisco Networking for a $25 gift card