cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
499
Views
0
Helpful
1
Replies

Cisco IPS 4240 Questions

shoaibalam
Level 1
Level 1

1. When we configure TCP resets, Shunhost, or Shunconnection in the "action" option of the IPS 4240, is this action taken on behalf of IPS through its Command and control port or the Monitoring port?

2. If through Monitoring port then if we take the "show interface" on the Switch for the SPAN port, its something like "line protocol down(monitoring)", then how come switch get resets from this port when its line protocol is down?

I have this confusion, any comments plz...

1 Reply 1

mustafa.mail
Level 1
Level 1

Hi,

Monitoing interface used to send the tcp rests. Command & Control interface is used for Shun.

Your Switch which is being monitored with either SPAN or VACL capture should accept incomming packets on SPAN or VACL capture port. Otherwise your tcp-rest feature will not work.

Regards,

Mustafa.