Placement of iPs for FW double

Hi all

We have basic set up: 2 Core SW (6513 - channeled port)--> ASA 2 (active / standby: running OSPF). ASAs DMZ--> 2 DMZ switches (2948 & 3560 channeled port).

Same core switches,--> second pair ASA via different vlan that the first pair (runs as well the OSPF). No DMZ.

IAM planning to add 4255 IPS infrastructure. With the current scenario, if I start with a single unit, I'll be able to monitor all the traffic (inside the fw couples and DMZ) reserve and on active connections. If not possible with one unit 'inline', what about placing the IPS in surveillance mode and and using Span and Rspan 6513 ability, it will be possible to "monitor" all segments of the DMZ (2 augL) and Interior (total 4)?

TIA

MS

Place a sensor in-line with a double firewall IPS asking for trouble. You have created a single point of failure.

Your 4255 has several interfaces of follow-up. I cover one of each switch and use your 4255 promiscious mode.

Alternatlely, if your firewall double are active / standby, you could put the 4255 online in the active path and monitor Promisciously the path of the previous day.

Always plan on your sensor goes down, Cisco will not disappoint you.

-Bob

Tags: Cisco Security

Similar Questions

  • IP address: where can I find the ips for outgoing incoming mail adreesss

    where can I find the adreesss ips for outgoing mail

    You have to bring (and do you mean the server names) from your ISP or, where appropriate, your separate email provider.

    If you mean where they are on your system, you must provide the program messaging and the version and maybe able to tell or refer you to someone who can we'lll.

    In Windows Mail, you would look in tools / accounts / properties / servers.  In Outlook 2007, you'd look in tools / account settings / and double-click the account in question.  Others are different.

    I hope this helps.

    Good luck!

    Lorien - MCSA/MCSE/network + / has + - if this post solves your problem, please click the 'Mark as answer' or 'Useful' button at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • ASA - several IPS for VPN

    I'll put up Anyconnect to replace our customers of Cisco IPsec VPN, since it is end of life. A part of the process is to get an SSL certificate and a FULL domain name to use for this. I've got that and it is applied to the ASA very well. Now we don't get these warnings to the subject it is not not sure and such.

    The problem is that we use a non-standard port for the SSL VPN from 443 is already sent to an internal device. I have unused public addresses to the external interface of the ASA, but I don't know how I could use them. I would like to have a different IP address for SSL VPN, so I don't have to mess with the port forward that is currently in place. I read on proxy arp, but that looks like it could be a problem. I could have someone connect another cable to a different interface on the ASA (5512-X) and assign this static interface I want for the VPN, but I'm not sure it will work well. We have connections VPN site to site in place as well. Can I have the ASA listening on two different interfaces at the same time?

    Recap:

    IP 1 - address primary NAT, Site at tunnels put end here, some Cisco IPsec VPN terminate customer

    IP 2 - want to have all customers of Anyconnect connect here, to migrate all legacy Cissco IPsec clients until they are all over Anyconnect.

    Key is that I can not stop listening on IP 1 for site-to-site connections.

    Thoughts?

    Thank you!

    On the SAA, you cannot use the additional IPS for VPN.

    If tcp/443 is already used for an external server, then I would reconfigure the DNS entry for it to use the second IP address that must be sent to the internal server. You can then use the IP interface of the ASA for AnyConnect.

  • I entered my incorectley IPS for Windows Live Mail so I can't send & receive emails.

    original title: IPS

    I entered my incorectley IPS for Windows Live Mail so I can't send & receive emails. What should I do to fix this please

    View all Windows Live and Hotmail questions in the appropriate forum found here:
    http://windowslivehelp.com/

  • Need drivers for camera double digital vivitar

    I want to download free drivers for the double camera vivicam 10.  does anyone know where to get them?

    From Internet Explorer

    Original title: camera double digital Vivitar

    Did you contact the Support of Vivitar again?

    [THX @here]

  • Just place an order for Photoshop and Premiere Elements. I ordered in error windows version. I need to change the Mac version. How?

    Just place an order for Photoshop and Premiere Elements. I ordered in error windows version. I need to change the Mac version. Already obtained serial numbers, but I have not downloaded anything. I called the customer service that they me transferred to HIM and HE asked me to go to the cat. Chat is always busy. How can I change the version before you download?

    Javifran1234,

    To cancel or change orders online, please visit this link:

    Cancel or change orders online

    Guinot

  • How can I reset my password for my digital signature I put in place earlier today for a bank loan, Signature authorization?

    How can I reset my password for my digital signature I put in place earlier today for a bank loan, Signature authorization?

    You cannot reset a password for a digital signature. If you have forgotten it, you will need to create a new.

  • As a gesture of goodwill, we can help you with the upgrade for PSE 13. We ask you to place the order for Adobe Photoshop elements 13 upgrade and then provide you with the serial number of the full version for the same product against the new upgra

    I have RECIVED YEAR EMAIL FROM ADOBE AS: as gesture of goodwill, we can help you with the upgrade for PSE 13. We ask you to place the order for Adobe Photoshop elements 13 upgrade and then provide you with the serial number of the full version of the product, even against the new order of upgrade"IS this UPGRADE FREE AND CE WHO SHOULD DO, HOW can I HAVE THIS UPGRADE?

    HOW I CAN PLACE THE ORDER AND IS IT FREE?

  • I have put in place for the double sided copies on Canon Pixma MX 922? Thank you

    Hello

    How can I get my Canon MX 922 to make double sided copies?  Thank you

    Wish they offered an instruction manual...

    Chrismiss56

    Hi chrismiss56,

    To copy both sides of the page, please select your PIXMA MX922 and follow these steps:

    1. press the button COPY.

    2. load the paper you want to print on in your PIXMA MX922.

    3. load the original document on the glass exhibition or in the ADF.

    4. press on the right-hand (under Print on the LCD settings) button.

    5. press up or down arrow select-sidedPrintSetting 2 ot.

    6. press on the arrow right or left to select 2 sides.

    7. press the button color for color copying, or the black button in black & white copy.

    Will depend on where you have placed the original, additional screens will be displayed.  Follow the prompts to complete the copy.

  • How to place multiple orders for the same address on the photos?

    Hello!

    I created several books on Photos and I would like to get printed and shipped to my address.

    Unfortunately, it seems that it is only possible to place an order at the announcement of time (a book both in my case) so pay the shipping costs for each order/book.

    Am I missing something here?

    Thank you in advance for your help!

    You can combine only multiples of the same item in an order.  If you have created several books, you will need to pay the shipping costs for each of them separately.

  • How to ensure that the value of a control (for example double) initializes the last value when the VI has been closed?

    I use a cluster as a control. I would like to double in this control to automoatically values to fill their last values set when the VI is opened or accessed for the first time. It would be great if someone could point out for me. Thanks in advance!

    In my opinion, the configuration files are the easiest method and the best.  Simply save your last values to the file when your code ends.  At the beginning of your code, to read the file and fill in the controls with the values read.  With the configuration files, the section name can be the name of the cluster, and key names can be control names.

    I know OpenG has some pretty nice to do, but I prefer to use the native functions OR when I can.  When porting to a new system, there is no need to copy any additional screws library (OpenG library).  The native DV come with Labview.

  • Place a button for calibration of the strain gages on the façade

    Hello

    I'm relatively new to LabVIEW, and I'm trying to place a button on the front of a VI that is designed to graphically view statements for voltage of several strain gauges. I tried to use the offset calibration DaqMX bridge Subvi initially, but is not the same thing as the calibration button of the strain on the device tab in MAX.

    Can someone help me to do it properly? I know that's not much more difficult to just do the calibration in MAX, but my supervisor is looking for the VI to be as simple as possible for the user.

    Thank you!

    for a project that I use on average for gauge calibration chain
    I Place a button when the press op that he finds the average of the last ten value of voltage and then I use it as V0 in the vi strain using shift register
    is this great method for you?
    If so I can give you examples of code

  • Office Pro 8500 A910: settings is more standard for printing double-sided on Office Pro 8500 A910?

    We always used standaard duplex until a few months after a update for the HP printer, now he can't keep remembering settings. I need to reset duplex printing before each printing. Very annoying. You can find it under: Preferences/options tab system/then the check mark to: printing to HP accessories.

    Each print, I have set the printer for duplex printing. Is there another way? I've got MAC iOS 10.10.  Greetings, Pauline

    Hello @Jamieson,
    First of all, I want to thank you for your answer!
    I will try to follow your advice, step by step. : happy smiley:
    Reset the power supply. Did not work.
    Updates work automatically.
    Gel and setting up the printer, did not work.
    Only the utility disc repair disk permissions feature, I don't understand, sorry, not an expert...
    But still I can print double-sided of my i-Phone in i - Pad! It's so weird. I'll ask my partner: wink smiley:
    So I hope you know any sort well!

  • My entry point jumps away from the place where I post (and double-click) my cursor

    I had a lot of trouble with the slider staying in the place where I have the position of the entry point.  I will place the cursor at the end of a sentence - or even in the middle of a sentence for an insert.  Then, when I start typing, the new text will eventually be listed somewhere else in the document.  This occurs in Microsoft Word (2007) and a single Note (2007).  The entry point for the text does not stay when I click the cursor for some reason any.  Does anyone else have this problem?  I work in Vista Home Premium on a Dell Studio 1500 series.  I use a Kensington Expert Mouse to operate the cursor.

    Antaresting,

    Its probably your touchpad. Turn off your touchpad while you write. Sometimes I accidentally type my touchpad with my Palm when I type. Thank you, Jeremy M - Support Engineer

  • Best IPS for my XPS15Z monitor

    Hi, I am a photographer and am looking for a new independent monitor as the limitations of the monitor of my laptop are more obvious I have more experience. I was watching the monitor U2412M but it doesn't have an HDMI port, and only display in the XPS15Z port is HDMI. The U, I am far from technique regarding the color and resolution but it seems, even with an adapter, there could be problems? Anyone have any ideas or recommendations for the best IPS monitor to go with my laptop to give accurate colors? My budget stretch across price + $1,000 of some other Dell monitors. I think that 24 "enough. On another note, a basic question, but I have to use my computer laptop keyboard/mouse (wide screen) or can I buy another keyboard and have my laptop on the side somewhere? Appreciate very much all the advice. Thank you!

    I don't know if this GPU has the issue. Using DP or HDMI, some video cards called our recent monitors TV and the pilot will limit the dynamic range of 16-235. You will need to manually select all 0-255 under the agreement early in the graphics driver settings. Or use the toggler.

Maybe you are looking for