07-14-2011 02:07 PM - edited 03-10-2019 05:24 AM
Hi,
Any one knows cisco IPS support failover(active/stanby)?.Please let me know !!!
Rajeswar.
07-15-2011 07:53 AM
Not in the same way the Cisco Firewalls support failover. There is no synchronization of TCP state between two IPS sensors placed in a High Availability pair. This become a problem if you have a dual rail HA environment that is Active/Active (traffic flowing on both rails) and traffic is allowed to flow asynchronously (a single TCP session can leave via one rail and return via the other). Cisco sensors do not perform well when they can not track TCP state.
As far as I've seen, only McAfee IPS sensors have state synchronization failover as a feature, although Tippingpoint sensors are well suited for single sensors in asynchronously routed environments.
07-15-2011 11:31 AM
Simply, IPS is a layer 2 device, there is no HA.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide