Cisco IPS-4255-K9 Installation Guide - Page 27
TCP Reset Interfaces, Understanding Alternate TCP Reset Interfaces
UPC - 746320951096
View all Cisco IPS-4255-K9 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 27 highlights
Chapter 1 Introducing the Sensor How the Sensor Functions Note The IPS 4260 supports a mixture of 4GE-BP, 2SX, and 10GE cards. The IPS 4270-20 also supports a mixture of 4GE-BP, 2SX, and 10GE cards up to a total of either six cards, or sixteen total ports, which ever is reached first, but is limited to only two 10GE card in the mix of cards. TCP Reset Interfaces This section explains the TCP reset interfaces and when to use them. It contains the following topics: • Understanding Alternate TCP Reset Interfaces, page 1-9 • Designating the Alternate TCP Reset Interface, page 1-10 Understanding Alternate TCP Reset Interfaces Note The alternate TCP reset interface setting is ignored in inline interface or inline VLAN pair mode, because resets are sent inline in these modes. You can configure sensors to send TCP reset packets to try to reset a network connection between an attacker host and its intended target host. In some installations when the interface is operating in promiscuous mode, the sensor may not be able to send the TCP reset packets over the same sensing interface on which the attack was detected. In such cases, you can associate the sensing interface with an alternate TCP reset interface and any TCP resets that would otherwise be sent on the sensing interface when it is operating in promiscuous mode are instead sent out on the associated alternate TCP reset interface. If a sensing interface is associated with an alternate TCP reset interface, that association applies when the sensor is configured for promiscuous mode but is ignored when the sensing interface is configured for inline mode. With the exception of the IDSM2, any sensing interface can serve as the alternate TCP reset interface for another sensing interface. The alternate TCP reset interface on the IDSM2 is fixed because of hardware limitation. Note There is only one sensing interface on IPS modules (AIM IPS, AIP SSM, and NME IPS). Table 1-3 lists the alternate TCP reset interfaces. Table 1-3 Alternate TCP Reset Interfaces Sensor AIM IPS AIP SSM-10 AIP SSM-20 AIP SSM-40 IDSM2 IPS 4240 IPS 4255 Alternate TCP Reset Interface None None None None System0/11 Any sensing interface Any sensing interface OL-18504-01 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 1-9