Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

IPS 4255 (any possible loops)

All,

I hope you are well and can pls assist with my following request

We have an IPS4255 installed in our data centre and want to cature traffic from all PCI related servers

we are planning to use all 4 interfaces on the IPS

all interfaces will connect to seperate switches.

The switches are a combination of 3750X and Nexus 5000s.

WE will have a local span running on the switches and the destionation of the span will be one of the interfaces on the IPS.

Below is an example for the destination port that connects to the IPS from one of the switces

interface GigabitEthernet1/0/10

description PCI-SPANPORT-IPS4200

switchport mode access

switchport nonegotiate

speed 1000

duplex full

udld port aggressive

spanning-tree guard root

monitor session 2 source interface Gi1/0/1

monitor session 2 destination interface Gi1/0/10

monitor session 2 filter ip access-group IPS-SPAN

My question

It there a possibility for a loop to occur between the IPS and the 4 switches connected to the differeent ports on the IPS 4255 will the IPS tranmit ot recive BPDU etc or bridge between switches.

Kind Regards,

Zee

1 REPLY

IPS 4255 (any possible loops)

Hello Zeeshan,

What mode will u run on the IPS, I can see it will not be inline so I do not see a way a loop can form.

But anyway confirm that to us

Rate all of the helpful posts!!!

Regards,

Jcarvaja

Follow me on http://laguiadelnetworking.com

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
687
Views
4
Helpful
1
Replies
CreatePlease to create content