Inline Interface Pair Mode; Inline Vlan Pair Mode - Cisco IPS 7.1 Installation Manual

Intrusion prevention system appliance and module
Table of Contents

Advertisement

How the Sensor Functions
The SPAN/Monitor configuration is valuable when you want to assign different IPS policies per VLAN
Note
or when you have more bandwidth to monitor than one interface can handle.
For More Information
For more information on promiscuous mode, see

Inline Interface Pair Mode

Operating in inline interface pair mode puts the IPS directly into the traffic flow and affects
packet-forwarding rates making them slower by adding latency. This allows the sensor to stop attacks by
dropping malicious traffic before it reaches the intended target, thus providing a protective service. Not
only is the inline device processing information on Layers 3 and 4, but it is also analyzing the contents
and payload of the packets for more sophisticated embedded attacks (Layers 3 to 7). This deeper analysis
lets the system identify and stop and/or block attacks that would normally pass through a traditional
firewall device.
In inline interface pair mode, a packet comes in through the first interface of the pair on the sensor and
out the second interface of the pair. The packet is sent to the second interface of the pair unless that
packet is being denied or modified by a signature.
You can configure the ASA IPS modules (ASA 5500 AIP SSM, ASA 5500-X IPS SSP, and
Note
ASA 5585-X IPS SSP) to operate inline even though they have only one sensing interface.
If the paired interfaces are connected to the same switch, you should configure them on the switch as
Note
access ports with different access VLANs for the two ports. Otherwise, traffic does not flow through the
inline interface.
Figure 1-3
Figure 1-3
Router

Inline VLAN Pair Mode

The ASA IPS modules (ASA 5500 AIP SSM, ASA 5500-X IPS SSP, and ASA 5585-X IPS SSP) do not
Note
support inline VLAN pairs.
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
1-16
illustrates inline interface pair mode:
Inline Interface Pair Mode
Traffic passes
through interface pair
Sensor
Promiscuous Mode, page
VLAN A
Switch
Host
Chapter 1
Introducing the Sensor
1-14.
OL-24002-01

Advertisement

Table of Contents
loading

Table of Contents