Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPS 4240 in test mode?

Is there a way to configure the IPS 4240 to monitor traffic but not to block connections? We are currently evaluating the device but would prefer it to monitor rather than block any live traffic at this stage. We have configured an event action filter for all sigs and all source/destination IPs to remove all the deny functions but does anyone have a different way of doing this?

1 REPLY
Gold

Re: IPS 4240 in test mode?

Simon -

You should set up your 4240 in promiscous mode (as opposed to in-line). Take a switch that is passing all the traffic you'd like to inspect and turn on port spanning with the monitor session commands:

http://www.cisco.com/en/US/docs/ios/12_3t/lanswitch/command/reference/lan_m1gt.html#wp1021715

Then feed the stream into your sensor as an input only.

134
Views
0
Helpful
1
Replies