cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1511
Views
0
Helpful
3
Replies

Virtual IPS/IDS design question.

David Kleberson
Level 1
Level 1

Hi! I'm having some problems with understanding the design of virtual IPS/IDS.
I know how to do it with hardware IPS/IDS, when you have one physical interfaces specified to handle traffic and another physical interface to to send inspected traffic back to Core.

My question is how do people do it with virtual firewall? I mean how it is possible to configure a server running on VMWare to receive SPAN session (in IDS case) or something like that.

I hope I can clarify my concern.

2 Accepted Solutions

Accepted Solutions

nspasov
Cisco Employee
Cisco Employee

You can actually do both. If you just want to monitor (IDS) then you will have to dedicate a physical port on your VM server and span traffic to it. For more info on that check this link:

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004099

If you want to place the virtual appliance inline, then you will have to dedicate two physical ports from your VM server. One of those ports will be used for the outside zone and the other for your inside zone. 

I hope this helps!

 

Thank you for rating helpful posts!

View solution in original post

Yes, otherwise you can't really put it truly inline if other hosts/vlans are about to traverse around it :)

View solution in original post

3 Replies 3

nspasov
Cisco Employee
Cisco Employee

You can actually do both. If you just want to monitor (IDS) then you will have to dedicate a physical port on your VM server and span traffic to it. For more info on that check this link:

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004099

If you want to place the virtual appliance inline, then you will have to dedicate two physical ports from your VM server. One of those ports will be used for the outside zone and the other for your inside zone. 

I hope this helps!

 

Thank you for rating helpful posts!

Neno, thank you for your reply. Does it mean that I have to sacrifice 1 or 2 physical ports of a host that is running VMware or HyperV?

Yes, otherwise you can't really put it truly inline if other hosts/vlans are about to traverse around it :)

Review Cisco Networking for a $25 gift card