iii
Cisco Intrusion Prevention System Appliance and Module Installation Guide for IPS 7.1
OL-24002-01
C O N T E N T S
About This Guide
xv
Contents
xv
Audience
xv
Organization
xvi
Conventions
xvi
Related Documentation
xvii
Where to Find Safety and Warning Information
xvii
Obtaining Documentation, Using the Cisco Bug Search Tool, and Submitting a Service Request
xviii
C H A P T E R
1
Introducing the Sensor
1-1
Contents
1-1
How the Sensor Functions
1-1
Capturing Network Traffic
1-1
Your Network Topology
1-3
Correctly Deploying the Sensor
1-3
Tuning the IPS
1-3
Sensor Interfaces
1-4
Understanding Sensor Interfaces
1-4
Command and Control Interface
1-5
Sensing Interfaces
1-6
Interface Support
1-6
TCP Reset Interfaces
1-11
Interface Restrictions
1-12
Interface Modes
1-14
Promiscuous Mode
1-14
IPv6, Switches, and Lack of VACL Capture
1-15
Inline Interface Pair Mode
1-16
Inline VLAN Pair Mode
1-16
VLAN Group Mode
1-17
Deploying VLAN Groups
1-18
Supported Sensors
1-18
IPS Appliances
1-20
Introducing the IPS Appliance
1-20
Appliance Restrictions
1-21