IPS Redundancy Pair and Etherchannel

Guys,
Do yo have any experience with IPS redundandy ?
i have idea about it ?
|-----------|
|-----------| ---link-1--- IPS-1
|-switch-|
|-----------| ---link-2--- IPS-2
|-----------|
Two IPS (IPS-1 and IPS-2) is deployed in "out of bound" to one switch (I know it can be deployed use two switch and use inline topology but i don't have other switch :D). Link-1 and link-2 is etherchannel trunk. Etherchannel trunk carry vlan inside and vlan outside. In IPS-1 and IPS-2 there are mapping vlan for that vlan (inside <--> outside).
What do you think guys ?

Hi,
how did you solve this? Have you tried load-balancing using multichassis etherchannel?
Radim

Similar Messages

  • IPS Appliance (4500 and 4300) interface redundancy

    Hello all,
    Around interface redundancy (A.K.A. interface bonding): our design actually includes a catalyst switch and a couple of IPS appliances 4500, an etherchannel configured with 2 SPF+ cables, one to each IPS. As you might know this are 10Gbps links. This as you see has a layer of resilience by having 2 IPS etherchanneled into the Catalyst.
    Now, if one cable fails or interface fails, can we configure any sort of interface bonding or semi-automatic setup with a extra link (in standby or not active) given that we might have spare 10Gbps ports on the switch AND on the IPS? Is there a best practise or something around this? I think the ASA firewalls have a command called "member-interface" which allow this type of redundancy but I think I have not seen this on the CR for the IPS OS. ( see http://yurisk.info/2010/08/23/redundant-interfaces-in-cisco-asa/)
    Cheers!
    Heber

    Cyrus,
    It kinda does, it is called Event action filters, where you can excempt host/subnets for triggering certain signatures.
    http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_event_action_rules.html
    Whatever you put on them, wont trigger the signatures you dont want it to trigger.
    Hope it helps.
    Mike

  • CSS redundant interface and DNS server

    We're attempting to implement a pair of CSS's using redundant ASR and GSLB where the CSS's act as DNS servers.
    But I'm not sure if the 2 features are compatible. The CSS's answer DNS queries to their direct interface but not the redundant interface.
    Does anyone have any suggestions or work-arounds? We're running version 8.20.
    TIA,
    Dan

    Dan doing some research I can see that the option to configure redundant-interface to resolve dns queries is not included on CSS 11500 series, this from the documentation.
    On the document for CSS 11000 series that I provided before shows:
    Configuration Requirements and Restrictions
    The following requirements and restrictions apply to the configuration of this feature.
    •You can configure this feature only on Cisco 11000 series CSSs (not 11500)
    If I look at the redundant-interface configuration on old CSS 11000 series I see the option for dns:
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11000series/v6.10/configuration/advanced/guide/VIPRedun.html#wp1067528
    Look at this line:
    dns-server - Keyword that enables the CSS to respond to DNS queries destined for the redundant interface IP address. For more information, see the "Configuring a Redundant Virtual Interface to Respond to DNS Requests" section.
    On new CSS 11500 series this option is not available:
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20_v8.10/configuration/redundancy/guide/VIPRedun.html#wp1067528
    I am trying to find if there is any workaround but so far semms that is expected to miss this feature on CSS11500.

  • I am trying to pair my cell phone and tablet using Messages   App,  but only MMS messages will come through on my tablet.   I've tried pairing and unpaired,  reinstalling app on my tablet,  and can't figure it out.   Any idea how to fix this?

    I am trying to pair my cell phone and tablet using Messages   App,  but only MMS messages will come through on my tablet.   I've tried pairing and unpaired,  reinstalling app on my tablet,  and can't figure it out.   Any idea how to fix this?
    Thanks

    I Shared my most ridiculous situation but didn t log under your problem.
    sorry, I gave you your answer under sunshine99 or Dianna. I want out and you want in.
    if you not find just email me at [removed]
    thanks
    Personal information removed as required by the Verizon Wireless Terms of Service
    Message was edited by: Admin Moderator

  • My wireless keyboard no longer connects with my iMac since changing the batteries. It now shows as not connected, not paired and not configured. A friend recently connected his iPad to the iMac and since then the problem started. Any ideas to resolve this

    My wireless keyboard no longer connects with my iMac since changing the batteries. It now shows as not connected, not paired and not configured. A friend recently connected his iPad to the iMac and since then the problem started. Any ideas to resolve this?

    a friend told me that he wants my os x cd for my macbook pro to upgrade his imac.
    The discs that come with your Mac are "machine specfic" and cannot be used on another Mac.

  • Can I pair and use more than one set of bluetooth speakers at the same time on my ipod touch 4.0

    can I pair and use more than one set of bluetooth speakers at the same time on my ipod touch 4.0 or Iphone 4s or Ipad 2?

    You can only connect to one device at a time using Bluetooth, See article below for more information.
    http://support.apple.com/kb/ht1664
    While your iOS device can maintain multiple pairing records, it can only connect to one headset or hands-free device at a time. This prevents your iOS device from sending your data to the wrong Bluetooth accessory.

  • Bluetooth paired and connected, but not showing up in device list

    I have a iphone 4s and a plantronics discovery 975.  It was working fine, I don't recall doing any updates...  But now, it's showing paired and connected, but when I make a call, it's not connecting and doesn't sho up in the the device options - only shows speaker.  I already did the 'forget device' and re-paired it and it still won't work.  If I press the call button twice on the bluetooth, it'll call the last number dialed, so I know there's some connection...  I'm lost... Any help would be appreciated!

    Oh!  And here's another weird thing.  My nephew was visiting yesterday, helping me move furniture and he asked could he get on my wifi.  I opened the network lock and put the password in his phone myself and it never gave me a notification that he had connected.  Later, my dad came over and when his phone connected to my wifi, it let me know that he had connected.  Wonder what's different about these 3 devices (blu-ray, 2 iphones).  None were listed in the network map before I allowed them to connect yesterday.

  • HT1555 i just got a new apple tv but for some reason the remote only worked for about a min. and than it wount work at all. i tried to pair and unpair but nathing works but when i press a button the light on the apple tv turns off. what should i do?

    i just got a new apple tv but for some reason the remote only worked for about a min. and than it wount work at all. i tried to pair and unpair but nathing works but when i press a button the light on the apple tv turns off. what should i do?

    Have you held the menu and left arrow together for 6 secs ?  (I think you have from what you say).
    Also try unpowering and restarting AppleTV.
    AC

  • Should my iPhone 1 (iOS 3.1.3) with Bluetooth 2.0 (Handset HSP?) work with wireless earbuds with BT 4.0 and the Headset (and Handsfree, A2DP, AVRCP) protocol? They pair and connect; status bar looks good. But audio always comes out the speaker. Thx.

    Should my iPhone 1 (iOS 3.1.3) with Bluetooth 2.0 (Handset HSP?) work with wireless earbuds with BT 4.0 and the Headset (and Handsfree, A2DP, AVRCP) protocol? They pair and connect as expected (with a PIN); status bar looks good and shows Bluetooth active, and I even see the iPhone displays the battery levels of the wireless earbuds. But audio always comes out the speaker. (If I plug in wired headphones into the headphone jack then audio comes into the wired headphones, as expected.) I have rebooted the iPhone; I have had it forget about the wireless earbuds, and repaired and reconnected; I have reset all network settings. Thx in advance.
    PS: I understand that more recent versions of iOS have a way to choose where audio output goes (speaker, headphone jack, Bluetooth device). Does this older version of iOS? I could not find an option or setting.

    I've noticed this lately as well, with my iPhone 4. I couldn't confidently pin it directly on any particular iOS update, but my iPhone used to automatically connect up via Bluetooth with my Prius's handsfree feature, and now it doesn't. I work with a CE-based device at my job, with Bluetooth capability, and I used to test out that feature by having it discover my iPhone. This no longer works either.
    What I have found (not really a solution, but it does work and may be a clue for Apple) is that if I simply go to the Settings app then the General -> Bluetooth screen and let it sit there, it will pair right up with my car within a few seconds. Bluetooth is always on, and always says "Now Discoverable" at the bottom of the settings screen.

  • NEED HELP ASAP When I put my headphones in the music will play out loud. This has happened to another pair of my ear phones and I thought. They were broken so I brought another pair and they still won't work

    Okay so it basically explains everything in the summary I haven't had ear phones in a long time because they always break so then I found a old pair and then I put it in, but when I put the ear phones in the music started to play aloud .so, I thought they were still broken  so I brought a new pair and the same thing happened??  Did I  change the settings on accident or something some body please help me!!

    Sorry all my old isp can do is send out an engineer, and has no forum, but my new isp BT has
    i know you can't talk to BTW for me, but some genral BB user help and advice would be nice as this is regarding a move to BT within the next few days

  • Read start time of time pair and compare it in a PCR

    Hi All
    Created following PCR to check if th start time of the time pair is 09:30 or not. If it 0930 than I need to check the end time as well.
    000010            D HRS=PBEG  HRS?0900
    000020 *
    000030 =          D HRS=PEND  HRS?1730
    000040 = *
    000050 = =       HRS=DZ007 HRS-00.50 ADDDBZ007Z
    But the schema is processing only till line 20. As the start time of the time pair is 0930 it should go and check the end time.
    I would like to know if correct operations are used to capture the start time of time pair and compare?
    Any help will be much appreciated.
    Thanks

    Hello;
    Your pcr is wrong.
    000010 D HRS=PBEG HRS?0900
    000020 *
    000030 = D HRS=PEND HRS?1730
    000040 = *
    000050 = = HRS=DZ007 HRS-00.50 ADDDBZ007Z
    This is your rule. It checks whether it is 09:00 or not. If it is 09:00 it checks end time.
    000010 D HRS=PBEG HRS?09.50
    000020 *
    000030 = D HRS=PEND HRS?17.50
    000040 = *
    000050 = = HRS=DZ007 HRS-00.50 ADDDBZ007Z
    Beside you can not check it as 17.30 it should be out of 100.
    I mean 17:30 is 17.50 and 17:15 is 17.25
    Regards;
    Okan

  • Router NME IPS - use promiscuous and inline mode simultaneous

    Hi all,
    we are using the IPS module NME-IPS-K9 on a Cisco 2951 router. We like to use the IPS in promiscuous and inline mode simultaneous. For example traffic from a client to a server should pass through the IPS. But the IPS should only recieve a copy of the VoIP traffic.
    In the interface configuration mode the following command is set.
         ids-service-module monitoring promiscuous access-list 101
    If I try to set a interface to inline mode I get the following message:
         "Only either Inline or Promiscuous
         monitoring is supported on the router at one time.
         Please remove Promiscuous monitoring on all interfaces
         before configuring Inline monitoring. Only either Inline or Promiscuous
         monitoring is supported on the router at one time.
         Please remove Promiscuous monitoring on all interfaces
         before configuring Inline monitoring."
    Is there any way to use promiscuous and inline monitoring at the same time? Is there a firmware update available which includes this feature? Any other idears?
    IOS version of the router: 15.0(1)M4
    IPS version:  7.0(2)E4
    Kind Regards

    In promiscuous mode your sensor doesn't affect the traffic but it only listen and analyze it.
    In inline mode you direct all your traffic on this network segment you want to protect to IPS and it analyze it and block some actions according to your settings.
    It is the main difference. Which mode to prefer must be your decision.

  • ATV 2 stopped working. The connections are good, the remote is paired and working, but the menus come and go off sporadically, and the white light just blinks continuously.

    I bought ATV 2 about two weeks ago.  The setup was easy and I set up my Home Sharing, screensavers, and I was watching Netflix within about 20 minutes.  I had a good week of no trouble and enjoyed the device immensely.  I updated the software when prompted and continued to watch movies and play music.  Then something happened: in the middle of viewing, ATV 2 stopped working, the screen went blank, and the little white light started blinking slowly.  When this happens, the ATV manual "troubleshooting" section merely says, "Apple TV is having problems."  ***?  Strangely, it would come on and act fine for a few moments as if nothing happended (for only a minute or two), then click off again.
    I attempted to RESET the device by using the Down/Menu combo -- nothing -- the white light blinks really fast but still no picture on the TV (just the Apple logo); I unplugged it and plugged it back in -- no fix; then, I RESTORED the device and had to re-enter Apple and Netflix account info, passwords, set up shared photo folders, etc.  Afterwards, it worked.  I watched movies right where I left off and went on with life until a few days ago when I wanted to finish a movie... The movie was going fine - no problems at all - until ATV 2 stopped working again! 
    So, the remote works [it is paired and sends commands as it should], the HDMI connection to HDTV is fine, the stereo receiver connection is fine (for audio, using an optical cable).  But the only thing on the TV is the Apple logo.  Resetting ATV 2 doesn't work; and I could restore it again but that seems like a HUGE waste of time, and something I am not prepared to do each time I want to use the device. 
    What could be the cause?  Wireless interferrence, software/update flaws, need for firmware, or malfunctioning hardware?   ATV 2 is a $100 paperweight until I get answers.

    After some sleuthing online, reading a compilation of Q&As here, and visiting the local Apple Store, I think the problem and "solution" may be found in HOW my ATV2 is connected to my stereo.  For some reason that I have not figured out, when the RECEIVER either switches from one setting to another, it somehow disrupts the ATV.
    The ORDER of how you turn ATV on and off is key.  If you start with everything OFF (ATV, HDTV, stereo Receiver), then turn on the receiver, then turn the HDTV, put the TV to the input setting that is connected to the ATV, THEN turn on the ATV by hitting the Play button on the remote. 
    Note: The ATV light may come on once the HDTV is turned on and put to the correct setting, but you will not see a picture on your TV yet.
    You should be up and running on ATV (without having to reset, unplug or restore). Apparently, I was using my universal remote that essentially turned everything (HDTV, Onkyo Receiver and, by extension, the ATV) on at the same time, confusing ATV and causing that evil blinking white light.  The ATV connection was lost.
    When you are done with ATV, you must put ATV to sleep FIRST... each time. The command is on the main menu, to the far right, at the bottom [Sleep Now].  Once you press Sleep Now, the ATV will go off.  THEN you can turn your receiver/HDTV off (or to whatever other setting you want for watching regular tv, music, etc.).  I was simply switching my HDTV and Receiver 'away' from ATV when I was done... But I would return to a blinking light and no ATV.  The solution above is a work-around that seems to do the trick.
    The thing Apple needs to fix is to make the "Sleep Now" command a simple process on the remote so you don't have to back out of everything you were watching to get to the main menu for the Sleep Now command. Or in the next update Apple merely needs to improve ATV2 so it can work no matter what order you open or close it on a HDTV/Stereo. 
    Note: Other people have suggested that you just hit the select or Menu button to put ATV to sleep, but that did NOT work for me.
    I figured this out through trial and error so I hope it works for you too.

  • Cisco 1900 switch support vtp version2 and etherchannel or not?

    cisco 1900 switch support vtp version2 and etherchannel or not?
    Please help and reference.
    Thank in advance

    Hello,
    Fast Etherchannel is supported on 1900 switches.
    Please refer the below URL for details:
    http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v9x/ee_scg/overview.htm#xtocid72765
    I "think" you need to have Enterprise Edition Software. In case if you have a standard version, then you need to purchase the upgrade kit to upgrade to enterprise version.
    As far as I know, VTP V2 is not supported on the 1900.
    By the way, 1900 swiches are End of Sale and the last date of support is July, 2007.
    http://www.cisco.com/en/US/products/hw/switches/ps574/prod_bulletin09186a008009257d.html
    I hope it helps.
    Regards,
    Arul

  • How many paired and active devices will bluetooth on IPad 3 support at a time ?

    How many (Paired and Active devices) will Bluetooth on the Ipad 3 sopport at a time?

    Actually that is not quite true. Bluetooth is limited to one connection per device profile. That is to say you cannot have two bluetooth headsets actively connected at the same time, but you could have a bluetooth headset and a heart rate monitor, as the hrt monitor and the headset would be using different profiles.

Maybe you are looking for