cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
287
Views
0
Helpful
1
Replies

ids

Ibrahim Jamil
Level 6
Level 6

Hi Experts

when y configure ur IPS as IDS , does the 1 sensing interface must be configured with same VLAN as the monitored Port

consider my public interface on my asa connected to switch1 int gig1/1(vlan 5) and the sensing interface connected to switch1 gig1/2

so the coniguration for IDS Mode on the Swich would be:

monitor seession 1 source inter gig1/1 both

monitor session 2 destination int gig1/2   <<<where the sensing interface of IPSis connected?

pls Advice

1 Reply 1

Hi Bro

Yes, these lines are fine;

monitor seession 1 source inter gig1/1 both

monitor session 2 destination int gig1/2  

You don’t need to configure the interface g1/2 to be in the same VLAN as g1/1, but if you wanna still do it, that’s fine too. I would do it, if I were you.

I believe the reason you’re asking this question is because you don’t see any traffic in your Cisco IPS appliance (running in IDS/promiscuous mode). Just ensure, that the port in the Cisco IPS appliance that’s connected to g1/2 is assigned a Virtual Sensor. This Virtual Sensor should be tagged with a signature definition, an event action rule and anomaly detection.

P/S: if you think this comment is useful, please do rate them nicely :-)

Warm regards,
Ramraj Sivagnanam Sivajanam
Review Cisco Networking products for a $25 gift card