I have IPS 4215 with 6.0 image, 4 sensing Interfaces anlong with the C&C,i m confused a litlte bit about the sensing interfaces across the network what am thinking is as follow:
IPS will be functions as inline mode
1) Two sensing interfaces bridged togather on the inside
2) Two sensing interfaces bridged togather on the outside, coz i have web server on the DMZ Need to be accessed from outside
but the inline rule said:traffic from interface to onother interface need to be checked , so how is that with traffic leaving my network to the internet so it nee to be checked either wich useless in this case coz i just need inspection to traffic comes from outside toward my web server and inspection the inside interfaces?
any help here in order to determine the ideal deployment for the sensors
Thanks a lot