Introducing The Idsm2 - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

IPS Modules
Figure 1-8
HTTP client
10.10.10.10
In
Figure 1-8
the DMZ web server (30.30.30.30). HTTP access to the DMZ web server is provided for all clients on
the Internet; all other communications are denied. The network is configured to use an IP pool (a range
of IP addresses available to the DMZ interface) of addresses between 30.30.30.50 and 30.30.30.60.
For More Information

Introducing the IDSM2

The Cisco Catalyst 6500 Series Intrusion Detection System Services Module (IDSM2) is a switching
module that performs intrusion prevention in the Catalyst 6500 series switch and 7600 series router. You
can use the CLI or IDSM to configure the IDSM2. You can configure the IDSM2 for promiscuous or
inline mode.
The IDSM2 performs network sensing—real-time monitoring of network packets through packet capture
and analysis. The IDSM2 captures network packets and then reassembles and compares the packet data
against attack signatures indicating typical intrusion activity. Network traffic is either copied to the
IDSM2 based on security VACLs in the switch or is copied to the IDSM2 through the SPAN port feature
of the switch. These methods route user-specified traffic to the IDSM2 based on switch ports, VLANs,
or traffic type to be inspected
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
1-24
DMZ Configuration
ASA security
appliance
Inside
10.10.10.0
DMZ
10.30.30.0
Web server
10.30.30.30
an HTTP client (10.10.10.10) on the inside network initiates HTTP communications with
For more information on setting up ASA, refer to the Getting Started Guides found at this URL:
http://www.cisco.com/en/US/products/ps6120/prod_installation_guides_list.html
For more information on installing the AIP SSM, see
For more information on configuring the AIP SSM to receive IPS traffic, refer to
AIP
SSM.
(Figure 1-9 on page
Outside
Internet
209.165.200.225
Installing the AIP SSM, page
1-25).
Chapter 1
Introducing the Sensor
HTTP client
HTTP client
6-3.
Configuring the
OL-18504-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents