promiscuous mode and inline pair

Unanswered Question


1) What's the difference between promiscuous mode and inline pair pair?

2) Where the necessary use of each mode?

3) if I have I-BANKING server located in the DMZ network, so what mode should be prefer

4)after the preferred mode then do I need to assign sensor on the outside and DMZ and the C&C in inside

Pls guide me

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
andrey.dugin Thu, 11/05/2009 - 04:49

In promiscuous mode your sensor doesn't affect the traffic but it only listen and analyze it.

In inline mode you direct all your traffic on this network segment you want to protect to IPS and it analyze it and block some actions according to your settings.

It is the main difference. Which mode to prefer must be your decision.

Adam Frederick Thu, 11/05/2009 - 12:33

with inline mode, do you actually plug the connection from the Internet in what would normally be your promiscous interface? I'm a little confused on how traffic is routed to the IPS first and then on to the firewall.


This Discussion