Inline Mode; Understanding Inline Mode; Configuring Inline Mode - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 5
Configuring Interfaces
Exit interface submode:
Step 10
sensor(config-int-phy)# exit
sensor(config-int)# exit
Apply Changes:?[yes]:
Press Enter to apply the changes or type
Step 11

Inline Mode

This section describes inline mode on the sensor, and contains the following topics:

Understanding Inline Mode

Operating in inline mode puts the IPS directly into the traffic flow and affects packet-forwarding rates
making them slower by adding latency. An inline IPS sits in the fast-path, which allows the sensor to
stop attacks by dropping malicious traffic before it reaches the intended target, thus providing a
protective service. Not only is the inline device processing information on layers 3 and 4, but it is also
analyzing the contents and payload of the packets for more sophisticated embedded attacks (layers 3
to 7). This deeper analysis lets the system identify and stop and/or block attacks that would normally
pass through a traditional firewall device.
In inline mode, a packet comes in through the first interface of the pair of the sensor and out the second
interface of the pair. The packet is sent to the second interface of the pair unless that packet is being
denied or modified by a signature.
You can configure AIP-SSM to operate inline even through it has only one sensing interface.
Note

Configuring Inline Mode

Use the inline-interfaces command in the service interface submode to configure inline interfaces.
AIP-SSM is configured for inline mode from the ASA CLI and not from the IPS CLI. For the procedure,
Note
see
The following options apply:
78-16527-01
Understanding Inline Mode, page 5-7
Interface Support, page 5-2
Configuring Inline Mode, page 5-7
Configuring ASA to Send IPS Traffic to AIP-SSM, page
inline-interfaces—Name of the logical inline interface pair.
default—Sets the value back to the system default setting.
description—Your description of the inline interface pair.
interface1—The first interface in the inline interface pair.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
14-3.
Inline Mode
5-7

Advertisement

Table of Contents
loading

Table of Contents