cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
0
Helpful
3
Replies

Changing from Promiscuous mode to In-Line mode

t.clark
Level 1
Level 1

I want to put the ISDM "in-line" between my internet edge router and my firewall (FWSM which is in the same chassis as the IDSM). In order to have traffic flow from the internet edge router into the IDSM, then out of the IDSM to the FWSM, I will need to set the IDSM interfaces in the appropriate VLANs. I cannot find the procedure for doing this in the documentation.

3 Replies 3

mherald
Level 1
Level 1

There is very little real documentation (that I have found) that covers this real well.

What I have found to work, think of it this way. Use two separate VLANs, VLAN 10 and VLAN 11 for example. Use the same IP address range over these two VLANs. Put the router in VLAN 10 and the firewall interface in VLAN 11 (or vice versa).

Then configure the IDSM two utilize the two VLANs as a VLAN pair. The only way those two interfaces can communicate (as they are on separate VLANs) is through the IPS module. The IPS module will bridge the two speparate VLANs with the Virtual Sensor Interface.

If there are hosts in the same VLAN, that will not traverse the IPS, but if the interfaces are in separate VLANS 10 and 11 in this example, they will traverse the IPS or any traffic that traverses this connection.

I hope this helps,

Mike

The idea above works in general, but there is a bit of a difference with hybrid vs IOS configurations.

The above post works for hybrid fairly well.

With IOS, there are some intrusion commands (3 or 4 of them) that are pretty self explainitory.

I dont have access to either chassis right now to send you a working Cat config.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: