ā08-29-2010 03:43 AM - edited ā03-10-2019 05:06 AM
Hi
I want proposed inline IPS in a network, but have option like ASA failover option. If one IPS failed then all network down then what to do.
so what I take decession IPS work under promicious mode . Pls expect good suggation.
Regards
Biplob
Solved! Go to Solution.
ā08-29-2010 01:31 PM
Unfortunately there is no failover mechanism for the IPS sensors. You can configure the sensor to fail open so that if the IPS engine fails traffic will bypass inspection and continue to flow.
ā08-29-2010 01:31 PM
Unfortunately there is no failover mechanism for the IPS sensors. You can configure the sensor to fail open so that if the IPS engine fails traffic will bypass inspection and continue to flow.
ā08-29-2010 09:22 PM
Thanks
ā08-30-2010 06:58 AM
Please keep in mind that the Fail Open capability of the Appliance sensors (except for the 4260 and 4270) are SOFTWARE Fail Open.
This means that if an IPS Sensor looses power you do not get put into bypass. If the sensor crashes badly enough you do not get put into bypass, because the sensor needs to realize that is has failed in order to put itself into bypass.
You have a few alternatives:
1) Put your single sensor in promiscious mode. No matter how badly it fails, you will not impact traffic. You will not get in-line IPS dropping of single packet attacks, but you can perform shunning (via and ACL) to a router or firewall.
2) Use an external Fail Open switch. There have been several forum discussions that describe how to use an external switch and STP to bypass a failed sensor. Switches are pretty reliable, more so than Sensors.
3) Use 2 sensors on daul rails with fail closed.
- Bob
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide