Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPS Online Failover

Hi

I want proposed inline IPS in a network, but have option like ASA failover option. If one IPS failed then all network down then what to do.

so what I take decession IPS work under promicious mode  . Pls expect good suggation.

Regards

Biplob

1 ACCEPTED SOLUTION

Accepted Solutions
New Member

Re: IPS Online Failover

Unfortunately there is no failover mechanism for the IPS sensors.  You can configure the sensor to fail open so that if the IPS engine fails traffic will bypass inspection and continue to flow.

3 REPLIES
New Member

Re: IPS Online Failover

Unfortunately there is no failover mechanism for the IPS sensors.  You can configure the sensor to fail open so that if the IPS engine fails traffic will bypass inspection and continue to flow.

New Member

Re: IPS Online Failover

Thanks

Gold

Re: IPS Online Failover

Please keep in mind that the Fail Open capability of the Appliance sensors (except for the 4260 and 4270) are SOFTWARE Fail Open.

This means that if an IPS Sensor looses power you do not get put into bypass. If the sensor crashes badly enough you do not get put into bypass, because the sensor needs to realize that is has failed in order to put itself into bypass.

You have a few alternatives:

1) Put your single sensor in promiscious mode. No matter how badly it fails, you will not impact traffic. You will not get in-line IPS dropping of single packet attacks, but you can perform shunning (via and ACL) to a router or firewall.

2) Use an external Fail Open switch. There have been several forum discussions that describe how to use an external switch and STP to bypass a failed sensor. Switches are pretty reliable, more so than Sensors.

3) Use 2 sensors on daul rails with fail closed.

- Bob

321
Views
0
Helpful
3
Replies