Interface Restrictions - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

How the Sensor Functions
Table 1-3
Sensor
IPS 4260
IPS 4270-20
NME IPS
1. This is an internal interface on the Catalyst backplane.
Designating the Alternate TCP Reset Interface
You need to designate an alternate TCP reset interface in the following situations:

Interface Restrictions

The following restrictions apply to configuring interfaces on the sensor:
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
1-10
Alternate TCP Reset Interfaces (continued)
Alternate TCP Reset Interface
Any sensing interface
Any sensing interface
None
When a switch is being monitored with either SPAN or VACL capture and the switch does not accept
incoming packets on the SPAN or VACL capture port.
When a switch is being monitored with either SPAN or VACL capture for multiple VLANs, and the
switch does not accept incoming packets with 802.1q headers.
Note
The TCP resets need 802.1q headers to tell which VLAN the resets should be sent on.
When a network tap is used for monitoring a connection.
Note
Taps do not permit incoming traffic from the sensor.
You can only assign a sensing interface as an alternate TCP reset interface. You cannot configure
the management interface as an alternate TCP reset interface.
Physical Interfaces
On modules (AIM IPS, AIP SSM, IDSM2, and NME IPS), all backplane interfaces have fixed
speed, duplex, and state settings. These settings are protected in the default configuration on all
backplane interfaces.
For nonbackplane FastEthernet interfaces the valid speed settings are 10 Mbps, 100 Mbps, and
auto. Valid duplex settings are full, half, and auto.
For Gigabit copper interfaces (1000-TX on the IPS 4240, IPS 4255, IPS 4260, and
IPS 4270-20), valid speed settings are 10 Mbps, 100 Mbps, 1000 Mbps, and auto. Valid duplex
settings are full, half, and auto.
For Gigabit (copper or fiber) interfaces, if the speed is configured for 1000 Mbps, the only valid
duplex setting is auto.
The command and control interface cannot also serve as a sensing interface.
Chapter 1
Introducing the Sensor
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents