cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1969
Views
5
Helpful
1
Replies

IPS with monitoring mode?

Machi Ma
Level 1
Level 1

Hello,

I just have new ASA 5555-X with IPS activate planning to setup.  However, how to setup so the IPS just running as a monitoring mode with so I can more easy to tune before active it.

Because even running promiscuous mode active take action to block the traffic which I wanna it should passing through.

Thanks!

1 Accepted Solution

Accepted Solutions

Dennis Perto
Level 5
Level 5

If the IPS is the Firepower module, here is the guide for installing:
http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html

You will need to use "monitor-only" to use it as an IDS instead of IPS.

sfr fail-open monitor-only

View solution in original post

1 Reply 1

Dennis Perto
Level 5
Level 5

If the IPS is the Firepower module, here is the guide for installing:
http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html

You will need to use "monitor-only" to use it as an IDS instead of IPS.

sfr fail-open monitor-only
Review Cisco Networking for a $25 gift card