Bypass Mode; Understanding Bypass Mode - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Chapter 5
Configuring Interfaces
To assign the interface to the virtual sensor, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Enter analysis engine mode to assign the interfaces to the virtual sensor:
Step 2
sensor# configure terminal
ssensor(config)# service analysis-engine
sensor(config-ana)# virtual-sensor vs0
sensor(config-ana-vir)# physical-interface GigabitEthernet0/1
Exit analysis engine mode:
Step 3
sensor(config-ana-vir)# exit
sensor(config-ana)# exit
sensor(config)#
Apply Changes:?[yes]:
Step 4
Press Enter to apply the changes or type

Bypass Mode

This section describes bypass mode on the sensor, and contains the following topics:

Understanding Bypass Mode

You can use the bypass mode as a diagnostic tool and a failover protection mechanism. You can set the
sensor in a mode where all the IPS processing subsystems are bypassed and traffic is permitted to flow
between the inline pairs directly. The bypass mode ensures that packets continue to flow through the
sensor when the sensor's processes are temporarily stopped for upgrades or when the sensor's
monitoring processes fail. There are three modes: on, off, and automatic. By default, bypass mode is set
to automatic.
Bypass mode was originally intended to only be applicable to inline-paired interfaces. Because of a
Note
defect, it does affect promiscuous mode. A future version may address this defect. We recommend you
configure bypass mode to automatic or off for promiscuous mode and not use the on mode.
There are security consequences when you put the sensor in bypass mode. When bypass mode is on, the
Caution
traffic bypasses the sensor and is not inspected, therefore, the sensor cannot prevent malicious attacks.
Note
Bypass mode only functions when the operating system is running. If the sensor is powered off or shut
down, bypass mode does not work—traffic is not passed to the sensor.
78-16527-01
Understanding Bypass Mode, page 5-9
Configuring Bypass Mode, page 5-10
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
to discard them.
no
Bypass Mode
5-9

Advertisement

Table of Contents
loading

Table of Contents