Tcp Reset Interfaces - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Chapter 1
Introducing the Sensor
The IPS 4260 supports a mixture of 4GE-BP, 2SX, and 10GE cards. The IPS 4270-20 also supports a
Note
mixture of 4GE-BP, 2SX, and 10GE cards up to a total of either six cards, or sixteen total ports, which
ever is reached first, but is limited to only two 10GE card in the mix of cards.

TCP Reset Interfaces

This section explains the TCP reset interfaces and when to use them. It contains the following topics:
Understanding Alternate TCP Reset Interfaces
The alternate TCP reset interface setting is ignored in inline interface or inline VLAN pair mode,
Note
because resets are sent inline in these modes.
You can configure sensors to send TCP reset packets to try to reset a network connection between an
attacker host and its intended target host. In some installations when the interface is operating in
promiscuous mode, the sensor may not be able to send the TCP reset packets over the same sensing
interface on which the attack was detected. In such cases, you can associate the sensing interface with
an alternate TCP reset interface and any TCP resets that would otherwise be sent on the sensing interface
when it is operating in promiscuous mode are instead sent out on the associated alternate TCP reset
interface.
If a sensing interface is associated with an alternate TCP reset interface, that association applies when
the sensor is configured for promiscuous mode but is ignored when the sensing interface is configured
for inline mode.
With the exception of the IDSM2, any sensing interface can serve as the alternate TCP reset interface
for another sensing interface. The alternate TCP reset interface on the IDSM2 is fixed because of
hardware limitation.
There is only one sensing interface on IPS modules (AIM IPS, AIP SSM, and NME IPS).
Note
Table 1-3
Table 1-3
Sensor
AIM IPS
AIP SSM-10
AIP SSM-20
AIP SSM-40
IDSM2
IPS 4240
IPS 4255
OL-18504-01
Understanding Alternate TCP Reset Interfaces, page 1-9
Designating the Alternate TCP Reset Interface, page 1-10
lists the alternate TCP reset interfaces.
Alternate TCP Reset Interfaces
Alternate TCP Reset Interface
None
None
None
None
System0/1
Any sensing interface
Any sensing interface
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
1
How the Sensor Functions
1-9

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents