I want to implement cisco IPS 4260.  Where should I place it in the network?

Posted on 2008-10-13
Last Modified: 2013-11-29
I have purchased one IPS for my network while i have active/standby PIX firewall running in my network.
Question by:tasnee

Expert Comment

ID: 22702532
If you only have one, and you're running in-line, I'd suggest placing it between your Interent Router and your Primary PIX.  This way, if your IPS fails, you'll still have an active Internet connection.

If the security of the IPS is more important that preventing Internet downtime, then place a switch behind the IPS and plug the outside interface to both PIXes into it.  This would be:  internet router -> IPS -> Switch -> both pixes.  This assumes the IPS you have is only a two-port device.  If it has more, you might be able to do the same thing without the switch.
LVL 32

Expert Comment

ID: 22702635

You can have up to 9 monitoring interfaces with this model, so you can put this device everywhere it makes sense for you. Obviously, you want to ensude you are protecting your critical assests so it depends how your are currently setup.

If you only have the default one interface then I would monitor/protect my critical inside assessts and craft
filters on your edge device to deny all traffic directed to the edge device and the firewall from outside sources.

harbor235 ;}
LVL 12

Expert Comment

ID: 22703766
I agree - put it wherever you want. Either way, it is standard practice to plug it into an interface on the PIX so that it can monitor whatever zone (be it the DMZ, inside, or outside) without any complications.
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

LVL 32

Expert Comment

ID: 22704130

Not sure what pugglewuggle means by plugging it into an interface on the PIX?

You use this device by connecting it to a switch that has SPAN capabilites, you can configure SPAN to monitor an entire vlan and forward that traffic to the sensing port on the IDS, very powerful.

How many ssensing interfaces do you have?

harbor235 ;}
LVL 12

Expert Comment

ID: 22706863
What I mean is that if you're trying to monitor zones on other interfaces of the PIX, it is best practice to the IPS sensor into an interface on the PIX so there is no double-NATing and confusion of the Sensor.
As far as using SPAN goes, make sure the total bandwidth of the monitored interfaces doesn't exceed the outgoing bandwidth of the mirrored port.

Author Comment

ID: 22708886
Actually I want to know what are the prons and cons if I place in either between internet routers and firewalls or before firewall?
LVL 12

Accepted Solution

Pugglewuggle earned 250 total points
ID: 22708964
The thing is that you can put it wherever you want... that's what's great about the IPS Sensor devices. You create virtual sensor zones wherever you want in the network by monitoring traffic on specified interfaces.
You usually want to connect it to the device that's acting as a "central hub" for all traffic - aka where all traffic has to cross to get to other networks. In many networks, this is either a core switch or a PIX/ASA (because PIXes connect several separate networks that you'd generally want to monitor like the outside, DMZ, everything coming/going to/from the inside, or other interfaces on the PIX. That's why I recommended the PIX.
What this will do is prevent the traffic from using up valuable bandwidth on the other interfaces of that device. The only real consideration here is making sure the backplane of the device you connect it to can handle all the monitoring traffic from the virtual sensors.
As far as where you want to place it goes (you mentioned between routers), you want to place it where the extra traffic it generates will create the smallest impact on your network bandwidth load. Routers have terrible throughput compared to a PIX or a switch, so putting it between routers usually isn't a good idea.
As I stated, the best place is generall directly to an interface on the PIX so traffic from other networks doesn't clog up every interface on the PIX but instead goes straight to the IPS Sensor through it's dedicated interface on the backplane (not a special port or anything, just a regular ethernet port like the others).
Also, use a gigabit port for the IPS if your PIX has one.

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
MAC address learning of Riverbed 4 41
Securing Access to Specific Folders 6 48
cisco 2800 cannot ping lan 4 18
Help with preventing downloading a zip file 10 35
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (…
Ensuring effective and secure communication in the age of healthcare BYOD.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now