Cisco IPS-4255-K9 Installation Guide - Page 94

Introducing the IPS 4270-20 - web protection

Page 94 highlights

Introducing the IPS 4270-20 Chapter 4 Installing the IPS 4270-20 Introducing the IPS 4270-20 Caution The BIOS on the IPS 4270-20 is specific to the IPS 4270-20 and must only be upgraded under instructions from Cisco with BIOS files obtained from the Cisco website. Installing a non-Cisco or third-party BIOS on the IPS 4270-20 voids the warranty. The IPS 4270-20 delivers up to 4 Gbps of performance in media-rich environments and 2 Gbps in transactional environments enabling you to protect fully saturated Gigabit networks and aggregate network traffic on multiple sensing interfaces. The IPS 4270-20 is also inline ready and has support for both copper and fiber NICs thus providing flexibility of deployment in any environment. Media-rich environments are characterized by content, such as that seen on popular websites with video and file transfer. Transactional environments are characterized by connections, such as E-commerce, instant messaging, and voice. Figure 4-1 demonstrates the spectrum of media-rich and transactional environments. Figure 4-1 Media-rich and Transactional Environments Commerce Gaming Streaming Video WWW Instant Messaging TRANSACTIONAL Voice Collaborative Workspaces Data Replication Web 2.0 MEDIA-RICH 250389 The IPS 4270-20 has two built-in GigabitEthernet network ports and nine expansion slots. The network port numbers are numbered from top to bottom beginning with 0 and the expansion slot numbers increase from right to left. The two built-in GigabitEthernet ports are used for management and are called Management0/0 and Management0/1. Management0/1 is reserved for future use. Slots 1 and 2 are reserved for future use. You can populate slots 3 through 8 with supported network interface cards. Slot 9 is populated by a RAID controller card and is not available for use by network interface cards. The sensing interfaces are called GigabitEthernet. Because of the multiple interfaces on the IPS 4270-20, it can cover multiple subnets, each of which have bandwidth requirements in the multi-T3 range or Gigabit range, and the multiple interfaces can be connected directly to the additional monitoring interfaces without needing to SPAN the traffic through a switch. For improved reliability, the IPS 4270-20 uses a compact flash device for storage rather than a hard-disk drive. The IPS 4270-20 supports two optional network interface cards, the 2SX interface card with fiber-optic ports, and the 4GE bypass interface card with copper ports that contains the hardware-bypass feature. Initially the IPS 4270-20 supports only the built-in interfaces and these two interface cards. The IPS 4270-20 supports a maximum of 16 sensing ports. Any additional configured ports will not be monitored and will not appear in the IPS configuration or statistics and no inline traffic will be forwarded on or between these ports. You receive the following error if you exceed the number of supported ports: The number of installed network interfaces exceeds the limit of 16. The excess interfaces are ignored. Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0 4-2 OL-18504-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412

4-2
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
OL-18504-01
Chapter 4
Installing the IPS 4270-20
Introducing the IPS 4270-20
Introducing the IPS 4270-20
Caution
The BIOS on the IPS 4270-20 is specific to the IPS 4270-20 and must only be upgraded under
instructions from Cisco with BIOS files obtained from the Cisco website. Installing a non-Cisco or
third-party BIOS on the IPS 4270-20 voids the warranty.
The IPS 4270-20 delivers up to 4 Gbps of performance in media-rich environments and 2 Gbps in
transactional environments enabling you to protect fully saturated Gigabit networks and aggregate
network traffic on multiple sensing interfaces. The IPS 4270-20 is also inline ready and has support for
both copper and fiber NICs thus providing flexibility of deployment in any environment.
Media-rich environments are characterized by content, such as that seen on popular websites with video
and file transfer. Transactional environments are characterized by connections, such as E-commerce,
instant messaging, and voice.
Figure 4-1
demonstrates the spectrum of media-rich and transactional
environments.
Figure 4-1
Media-rich and Transactional Environments
The IPS 4270-20 has two built-in GigabitEthernet network ports and nine expansion slots. The network
port numbers are numbered from top to bottom beginning with 0 and the expansion slot numbers increase
from right to left. The two built-in GigabitEthernet ports are used for management and are called
Management0/0 and Management0/1. Management0/1 is reserved for future use. Slots 1 and 2 are
reserved for future use. You can populate slots 3 through 8 with supported network interface cards. Slot
9 is populated by a RAID controller card and is not available for use by network interface cards. The
sensing interfaces are called GigabitEthernet.
Because of the multiple interfaces on the IPS 4270-20, it can cover multiple subnets, each of which have
bandwidth requirements in the multi-T3 range or Gigabit range, and the multiple interfaces can be
connected directly to the additional monitoring interfaces without needing to SPAN the traffic through
a switch.
For improved reliability, the IPS 4270-20 uses a compact flash device for storage rather than a hard-disk
drive. The IPS 4270-20 supports two optional network interface cards, the 2SX interface card with
fiber-optic ports, and the 4GE bypass interface card with copper ports that contains the hardware-bypass
feature. Initially the IPS 4270-20 supports only the built-in interfaces and these two interface cards.
The IPS 4270-20 supports a maximum of 16 sensing ports. Any additional configured ports will not be
monitored and will not appear in the IPS configuration or statistics and no inline traffic will be forwarded
on or between these ports. You receive the following error if you exceed the number of supported ports:
The number of installed network interfaces exceeds the limit of 16. The excess interfaces
are ignored.
250389
MEDIA-RICH
TRANSACTIONAL
Commerce
Gaming
Streaming
Video
WWW
Instant
Messaging
Voice
Collaborative
Workspaces
Data
Replication
Web 2.0