cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3984
Views
0
Helpful
2
Replies

IPS bypass mode

Hi,

Can we configure IPS in such a way that it can bypass traffic (few subnets) and inspect all other traffic in inline mode?

Aman

2 Replies 2

rhermes
Level 7
Level 7

If the traffic is passing thought your sensor it will get inspected.

You can create Event Action Filters or Event Action Overrides to change the sensor default behavior (sending events and potentially blocking traffic).

http://www.cisco.com/en/US/docs/security/ips/7.1/configuration/guide/idm/idm_event_action_rules.html

- Bob

Hello Aman,

What model sensor(s) do you have? This is achievable by using the Modular Policy Framework (MPF) on the ASA to forward traffic down to the IPS modules.

Thank you,

Blayne Dreier

Cisco TAC Escalation Team

**Please check out our Podcasts**

TAC Security Show: http://www.cisco.com/go/tacsecuritypodcast

TAC IPS Media Series: https://supportforums.cisco.com/docs/DOC-12758

Review Cisco Networking products for a $25 gift card