cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
971
Views
0
Helpful
1
Replies

IPS Promiscous VLAN Groups

evfodor
Community Member

Hi Team,

I'm planning to create the following IPS desing, but I'm not sure if it is working/configurable or not.

We have 2 IPSs (because of redundancy) running 7.1, in promiscouos mode. We have 2 routers/switches (again in redundancy) - has the same vlans configured on the swithces. VLAN 200 - this is VLAN-OFF on the diagram and VLAN 100 which is VLAN SR.

IPS is connecting to SW/RT-01 on G0/0 on trunk, and G0/1 to RT/Sw-02 on a trunk.

What i know is that i should create VLAN groups on IPSs:

physical-interfaces GigabitEthernet0/0

subinterface 1

vlan1 100

subinterface 2

vlan1 200

But i'm not sure about the other interface:

physical-interfaces GigabitEthernet0/1

subinterface 3

vlan1 100

subinterface 4

vlan1 200

Picture1.png

Does it work?

Thanks in advance!

Eva

Then need to add those to the correct virtual sensors:

Vs0:

Gigabitethernet0/0:1

Gigabitethernet0/1:3

vs1

Gigabitethernet0/0:2

Gigabitethernet0/1:4

1 Reply 1

rhermes
Level 11
Level 11

You do not need to run two virtual sensors in order to do this. Your signature policy will be the same for both sensors.

If you are feeding both sensors a promiscious feed from the switches, the sensors do not need to be configured for subinterfaces.

- Bob

Review Cisco Networking for a $25 gift card