I recently installed a 4260 IPS sensor. It is used to inspect traffic between a ISA server and the LAN. The ISA is formed from 3 real servers in NLB.
Each server is connected to 2 switches through 4 cables 2 in each switch, one in the internet VLAN and one in the IPS VLAN.
For some reason when i inspect the traffic it blocks the ISA traffic. No signature seems to be triggered but the traffic from the ISA server stops.
When i capture packets on the vs0 sensor i don't see any traffic from the ISA server for 5 to 10 min and after that it starts again to function.
The IPS inspects on two redundant pairs traffic that travels from the LAN to the ISA.
The IPS versionn is 6.1 E2
Any ideeas on what is causing this?