Inline Interface Pair Mode - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

How the Sensor Functions
For More Information

Inline Interface Pair Mode

Operating in inline interface pair mode puts the IPS directly into the traffic flow and affects
packet-forwarding rates making them slower by adding latency. This allows the sensor to stop attacks by
dropping malicious traffic before it reaches the intended target, thus providing a protective service. Not
only is the inline device processing information on Layers 3 and 4, but it is also analyzing the contents
and payload of the packets for more sophisticated embedded attacks (Layers 3 to 7). This deeper analysis
lets the system identify and stop and/or block attacks that would normally pass through a traditional
firewall device.
In inline interface pair mode, a packet comes in through the first interface of the pair on the sensor and
out the second interface of the pair. The packet is sent to the second interface of the pair unless that
packet is being denied or modified by a signature.
Note
You can configure the AIM IPS, AIP SSM, and NME IPS to operate inline even though these modules
have only one sensing interface.
Note
If the paired interfaces are connected to the same switch, you should configure them on the switch as
access ports with different access VLANs for the two ports. Otherwise, traffic does not flow through the
inline interface.
Figure 1-3
Figure 1-3
Router
For More Information
For a list of restrictions pertaining to IPS sensor interfaces, see
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
1-14
For more information on configuring SPAN/monitor on switches, refer to the following sections in
Catalyst 6500 Series Software Configuration Guide,
Configuring SPAN, RSPAN and the Mini Protocol Analyzer
Configuring SPAN on the Switch
Configuring Ethernet VLAN Trunks
Defining the Allowed VLANs on a Trunk
For more information on promiscuous mode, see
illustrates inline interface pair mode.
Inline Interface Pair Mode
Traffic passes
through interface pair
Sensor
8.7:
Promiscuous Mode, page
VLAN A
Switch
Host
Chapter 1
Introducing the Sensor
1-12.
Interface Restrictions, page
1-10.
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents