Cisco IPS-4255-K9 Installation Guide - Page 33
Inline VLAN Pair Mode, VLAN Group Mode
UPC - 746320951096
View all Cisco IPS-4255-K9 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 33 highlights
Chapter 1 Introducing the Sensor How the Sensor Functions Inline VLAN Pair Mode Note Inline VLAN pairs are not supported on the AIM IPS, AIP SSM, and NME IPS. You can associate VLANs in pairs on a physical interface. This is known as inline VLAN pair mode. Packets received on one of the paired VLANs are analyzed and then forwarded to the other VLAN in the pair. Inline VLAN pair mode is an active sensing mode where a sensing interface acts as an 802.1q trunk port, and the sensor performs VLAN bridging between pairs of VLANs on the trunk. The sensor inspects the traffic it receives on each VLAN in each pair, and can either forward the packets on the other VLAN in the pair, or drop the packet if an intrusion attempt is detected. You can configure an IPS sensor to simultaneously bridge up to 255 VLAN pairs on each sensing interface. The sensor replaces the VLAN ID field in the 802.1q header of each received packet with the ID of the egress VLAN on which the sensor forwards the packet. The sensor drops all packets received on any VLANs that are not assigned to inline VLAN pairs. Figure 1-4 illustrates inline VLAN pair mode. 253445 Figure 1-4 Router Inline VLAN Pair Mode Switch VLAN B VLAN A Host Trunk port carrying VLAN A and B Pairing VLAN A and B Sensor For More Information For a list of restrictions pertaining to IPS sensor interfaces, see Interface Restrictions, page 1-10 VLAN Group Mode Note You cannot divide physical interfaces that are in inline VLAN pairs into VLAN groups. You can divide each physical interface or inline interface into VLAN group subinterfaces, each of which consists of a group of VLANs on that interface. Analysis Engine supports multiple virtual sensors, each of which can monitor one or more of these interfaces. This lets you apply multiple policies to the same sensor. The advantage is that now you can use a sensor with only a few interfaces as if it had many interfaces. VLAN group subinterfaces associate a set of VLANs with a physical or inline interface. No VLAN can be a member of more than one VLAN group subinterface. Each VLAN group subinterface is identified by a number between 1 and 255. OL-18504-01 Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 1-15