Routing of VLANs on Cisco IPS 4240

Unanswered Question
Nov 17th, 2009

Hi Guys,

I have a setup where i have setup as follows


I have configured VLAN groups on the IPS. I can reach the servers on all the VLANs from the server farm and i can also reach the Server farm from the servers behind the IPS. The problem is that the servers behind the IPS on different VLANs can only communicate on ICMP. No other protocol is working. I have disabled the rules on the IPS. No success though.

What could the problem be here? Any insights?

Note: the ASA is the one doing the termination of the VLANs



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
rhermes Tue, 11/17/2009 - 09:12

Do you have vlan PAIRS configurged on your 4240? With VLAN pairs, traffic enters the IPS on one vlan and exits on another. So if your Serverfarm is on vlan 102 the IPS vlan pair might be 102-202 and the ServersonVLANs would be on vlan 202.

If that's not your problem, you can use the "packet display gi0/0" command to watch what traffic is actually making it to an interface on your sensor.


This Discussion