CHAPT ER
4-1
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
4
Configuring Interfaces
This chapter describes how to configure interfaces on the sensor. You configured the interfaces when you
initialized the sensor with the setup command, but if you need to change or add anything to your
interface configuration, use the following procedures. For more information on configuring interfaces
using the setup command, see Chapter 2, “Initializing the Sensor.”
This chapter contains the following sections:
Understanding Interfaces, page 4-2
Configuring Physical Interfaces, page 4-11
Configuring Promiscuous Mode, page 4-14
Configuring Inline Interface Mode, page 4-16
Configuring Inline VLAN Pair Mode, page 4-21
Configuring VLAN Group Mode, page 4-26
Configuring Inline Bypass Mode, page 4-33
Configuring Interface Notifications, page4-35
Configuring CDP Mode, page 4-36
Displaying Interface Statistics, page4-37
Displaying Interface Traffic History, page 4-40

Interface Notes and Caveats

The following notes and caveats apply to configuring interfaces on the sensor:
On appliances, all sensing interfaces are disabled by default. You must enable them to use them. On
modules, the sensing interfaces are permanently enabled.
There is only one sensing interface on the ASA IPS modules (ASA 5500-X IPS SSP and
ASA 5585-X IPS SSP), so you cannot designate an alternate TCP reset interface.
You can only assign a sensing interface as an alternate TCP reset interface. You cannot configure
the management interface as an alternate TCP reset interface.
You configure the ASA IPS modules (ASA5500-X IPS SSP and ASA 5585-X IPS SSP) for
promiscuous mode from the adaptive security appliance CLI and not fr om the Cisco IPS CLI.
You can configure the ASA IPS modules (ASA5500-X IPS SSP and ASA 5585-X IPS SSP) to
operate inline even though they have only one sensing interface.