Inline Vlan Pair Mode; Vlan Group Mode - Cisco IPS-4255-K9 - Intrusion Protection Sys 4255 Installation Manual

Intrusion prevention system appliance and module installation guide for ips 7.0
Table of Contents

Advertisement

Chapter 1
Introducing the Sensor

Inline VLAN Pair Mode

Inline VLAN pairs are not supported on the AIM IPS, AIP SSM, and NME IPS.
Note
You can associate VLANs in pairs on a physical interface. This is known as inline VLAN pair mode.
Packets received on one of the paired VLANs are analyzed and then forwarded to the other VLAN in the
pair.
Inline VLAN pair mode is an active sensing mode where a sensing interface acts as an 802.1q trunk port,
and the sensor performs VLAN bridging between pairs of VLANs on the trunk. The sensor inspects the
traffic it receives on each VLAN in each pair, and can either forward the packets on the other VLAN in
the pair, or drop the packet if an intrusion attempt is detected. You can configure an IPS sensor to
simultaneously bridge up to 255 VLAN pairs on each sensing interface. The sensor replaces the
VLAN ID field in the 802.1q header of each received packet with the ID of the egress VLAN on which
the sensor forwards the packet. The sensor drops all packets received on any VLANs that are not
assigned to inline VLAN pairs.
Figure 1-4
Figure 1-4
Router
For More Information
For a list of restrictions pertaining to IPS sensor interfaces, see

VLAN Group Mode

You cannot divide physical interfaces that are in inline VLAN pairs into VLAN groups.
Note
You can divide each physical interface or inline interface into VLAN group subinterfaces, each of which
consists of a group of VLANs on that interface. Analysis Engine supports multiple virtual sensors, each
of which can monitor one or more of these interfaces. This lets you apply multiple policies to the same
sensor. The advantage is that now you can use a sensor with only a few interfaces as if it had many
interfaces.
VLAN group subinterfaces associate a set of VLANs with a physical or inline interface. No VLAN can
be a member of more than one VLAN group subinterface. Each VLAN group subinterface is identified
by a number between 1 and 255.
OL-18504-01
illustrates inline VLAN pair mode.
Inline VLAN Pair Mode
Switch
VLAN B VLAN A
Trunk port carrying
VLAN A and B
Pairing VLAN A and B
Sensor
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.0
Host
Interface Restrictions, page 1-10
How the Sensor Functions
1-15

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents