Hardware Bypass; 4Ge Bypass Interface Card - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Hardware Bypass

Figure 3-3
Figure 3-3
GigabitEthernetslot_number/port_number is the expansion card interface naming convention for the
IPS 4260. The slot number is shown to the right of the slot in the chassis and the port number is
numbered from right to left starting with 0.

Hardware Bypass

This section describes the 4GE bypass interface card and its configuration restrictions. It contains the
following topics:

4GE Bypass Interface Card

The IPS 4260 supports the 4-port GigabitEthernet card (part number IPS-4GE-BP-INT=) with hardware
bypass. This 4GE bypass interface card supports hardware bypass only between ports 0 and 1 and
between ports 2 and 3.
To disable hardware bypass, pair the interfaces in any other combination, for example 2/0<->2/2 and
Note
2/1<->2/3.
Hardware bypass complements the existing software bypass feature in Cisco IPS. The following
conditions apply to hardware bypass and software bypass:
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
3-4
shows the 10GE interface card.
10GE Interface Card
4GE Bypass Interface Card, page 3-4
Hardware Bypass Configuration Restrictions, page 3-5
Hardware Bypass and Link Changes and Drops, page 3-6
When bypass is set to OFF, software bypass is not active.
For each inline interface for which hardware bypass is available, the component interfaces are set to
disable the fail-open capability. If SensorApp fails, the sensor is powered off, reset, or if the NIC
interface drivers fail or are unloaded, the paired interfaces enter the fail-closed state (no traffic flows
through inline interface or inline VLAN subinterfaces).
When bypass is set to ON, software bypass is active.
Software bypass forwards packets between the paired physical interfaces in each inline interface and
between the paired VLANs in each inline VLAN subinterface. For each inline interface on which
hardware bypass is available, the component interfaces are set to standby mode. If the sensor is
Chapter 3
Installing the IPS 4260
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents