Your IPS sensors can process only traffic that they receive on one of their interfaces. There are two methods for traffic capture:
Some common locations for deploying inline IPS include the following:
In promiscuous mode, you can use the following infrastructure devices to capture network traffic:
When using switches, you can use the following three mechanisms to configure Cisco switches to mirror traffic to you sensor's promiscuous interface:
To capture traffic by using the SPAN feature on a Catalyst 4000 or 6500 (running IOS), you need to use the monitor session command.
When configuring a VACL on Cisco IOS, you need to go through the following tasks:
When using the IOS Firewall (mls ip ids command), you need to go through the following steps to configure a VACL: