4215 placement and configuration
Posted on 2006-07-10
I am not very familiar with Cisco’s 4215 IDS. Currently our network is set up as follows:
Router>outside switch>Pix>Proxy>inside switch>LAN
I need to place this IDS on the network and configure it. Most of the literature that I have come across sates to place the device inline on the DMZ with two monitoring interfaces. I do not have the extra interfaces to do this. I only have one command and control (CC) and one monitoring interface. I’m not sure where the monitoring interface should be connected. I can add a DMZ switch to the Pix and connect the monitoring interface to the DMZ switch and the CC to the inside switch. Currently my Proxy server in connected directly to the Pix inside interface and I’m not sure if I need to disconnect it and place it elsewhere. Also, I’m not sure if I can connect the monitoring interface of the IDS directly to the Pix inside interface. I guess this may be more of a design question. Any help on this would be appreciated. BTW, I do have 5.0v on the 4215 and I would like it to perform as an IPS if possible without the extra interfaces.