4-8
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter4 Configuring Interfaces
Understanding Interfaces
Interface Configuration Restrictions
The following restrictions apply to configuring interfaces on the sensor:
Physical Interfaces
On the ASA IPS modules (ASA 5500-X IPS SSP and ASA 5585-X IPS SSP) all backplane
interfaces have fixed speed, duplex, and state settings. These settings are protected in the default
configuration on all backplane interfaces.
For nonbackplane FastEthernet interfaces the valid speed settings are 10 Mbps, 1 00 Mbps, and
auto. Valid duplex settings are full, half, and auto.
For Gigabit copper interfaces (1000-TX on the IPS 4345, IPS 4360, IPS 4510, and IPS 4520),
valid speed settings are 10 Mbps, 100 Mbps, 1000 Mbps, and auto. Valid duplex settings are
full, half, and auto.
IPS 4510 GigabitEthernet 0/0
GigabitEthernet 0/1
GigabitEthernet 0/2
GigabitEthernet 0/3
GigabitEthernet 0/4
GigabitEthernet 0/5
TenGigabitEthernet 0/6
TenGigabitEthernet 0/7
TenGigabitEthernet 0/8
TenGigabitEthernet 0/9
All sensing ports can be
paired together
Management 0/0
Management 0/1
2
IPS 4520 —TX GigabitEthernet 0/0
GigabitEthernet 0/1
GigabitEthernet 0/2
GigabitEthernet 0/3
GigabitEthernet 0/4
GigabitEthernet 0/5
TenGigabitEthernet 0/6
TenGigabitEthernet 0/7
TenGigabitEthernet 0/8
TenGigabitEthernet 0/9
All sensing ports can be
paired together
Management 0/0
Management 0/1
2
1. Does not currently support hardware bypass.
2. Reserved for future use.
Table4-3 Interface Support (continued)
Base Chassis
Added
Interface
Cards
Interfaces Supporting
Inline VLAN Pairs
(Sensing Ports)
Combinations Supporting
Inline Interface Pairs
Interfaces Not
Supporting Inline
(Command and Control
Port)