08-04-2006 11:28 AM - edited 03-10-2019 03:09 AM
I've got a IPS/IDS 4215 with its fastethernet 1/0 interface plugged into a switch, which is part of a dmz. That same switch is uplinked to the dmz interface of a PIX 515. I enabled some signatures for testing, including 2004 ICMP echo request, and I'm alerted about the events from my PIX running IDS, but the 4215 doesnt' detect it, which leads me to think my physical setup is incorrect. Perhaps because of the switch? I want to do some testing with promiscious mode, IDS, right now, not inline. What would the cabling look like for that?
Thank you,
Bill
Solved! Go to Solution.
08-05-2006 05:00 PM
Hi,
Try to enable/configure SPAN port (monitor session) on the switch. The port where the IDS was connected was not able to 'see' other traffics passing through the switch. SPAN/port mirroring is common if you need to use promiscious instead of inline. But if you use hub, you can just connect and start seeing traffic as hub behave differently from switch.
I assumed your DMZ switch has one (1) VLan.Configure your switch port connecting the IDS as destination port, while other ports as source port.
Follow the example in the following link and look for local SPAN.
Rgds,
AK
08-05-2006 05:00 PM
Hi,
Try to enable/configure SPAN port (monitor session) on the switch. The port where the IDS was connected was not able to 'see' other traffics passing through the switch. SPAN/port mirroring is common if you need to use promiscious instead of inline. But if you use hub, you can just connect and start seeing traffic as hub behave differently from switch.
I assumed your DMZ switch has one (1) VLan.Configure your switch port connecting the IDS as destination port, while other ports as source port.
Follow the example in the following link and look for local SPAN.
Rgds,
AK
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: