cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
832
Views
2
Helpful
2
Replies

IPS will support Filover?(Active/Stanby mode)

haivrajesh
Level 1
Level 1

Hi,

Any one knows cisco IPS support failover(active/stanby)?.Please let me know !!!

Rajeswar.

2 Replies 2

rhermes
Level 7
Level 7

Not in the same way the Cisco Firewalls support failover. There is no synchronization of TCP state between two IPS sensors placed in a High Availability pair. This become a problem if you have a dual rail HA environment that is Active/Active (traffic flowing on both rails) and traffic is allowed to flow asynchronously (a single TCP session can leave via one rail and return via the other). Cisco sensors do not perform well when they can not track TCP state.

As far as I've seen, only McAfee IPS sensors have state synchronization failover as a feature, although Tippingpoint sensors are well suited for single sensors in asynchronously routed environments.

Simply, IPS is a layer 2 device, there is no HA.

Review Cisco Networking for a $25 gift card