Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
New Member

IDS and PIX configuration in VMS

Hello...

We are looking to install both IDS and PIX components on one server. I was reading some of the items in the forum and was given the impression that it would be better if the two were split and installed on different servers. Can someone please share their results and what works best. Thanks

3 REPLIES
Cisco Employee

Re: IDS and PIX configuration in VMS

Hi,

PIXMC and IDSMC can definately co-exists. So installation of these on the same server is ok.

Install the Common services then PIXMC and then the IDSMC

Thanks,

yatin

New Member

Re: IDS and PIX configuration in VMS

With the two co-existing on the same server will there be a performance issue??? We have over 40 IDS sensors and over 30 PIX firewalls. Would you recommend the same set up??? We are essentially looking for the most optimal performance from this software.

Thanks

Allan

Cisco Employee

Re: IDS and PIX configuration in VMS

Hi Allan,

The VMS and the Management centers within it are robust enough to hand upto 300 devices. So you are ok having these 70 devices managed from a single server.

The thing that needs to be taken care of is the Security Monitor which receives the alarms / events from these devices. If the devices are too chatty, they will overwhelm the server, in that case, you could have the Security Monitor on a separate server and leave the IDS and PIX MCs on the other.

Security Monitor sustains receiving upto 500 events/sec. This is sufficient in most of the environments.

Hope this helps.

Yatin

95
Views
0
Helpful
3
Replies
CreatePlease to create content