4-11
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter4 Configuring Interfaces
Configuring Physical Interfaces
For More Information
For the procedure for configuring the physical interface settings, see Configuring Physical
Interfaces, page 4-11.
For the procedures for creating and deleting different kinds of interfaces, see Configuring Inline
Interface Mode, page4-16, Configuring Inline VLAN Pair Mode, page 4-21, Configuring VLAN
Group Mode, page 4-26, and Configuring Inline Bypass Mode, page 4-33.
For the procedure for configuring virtual sensors, see Adding, Editing, and Deleting Virtual Sensors,
page 5-4.
Configuring Physical Interfaces
Use the physical-interfaces interface_name command in the service interface submode to configure
promiscuous interfaces. The interface name is FastEthernet, GigabitEthernet, or PortChannel.
Note
You configure the ASA IPS modules (ASA5500-X IPS SSP and ASA 5585-X IPS SSP) for
promiscuous mode from the adaptive security appliance CLI and not fr om the Cisco IPS CLI.
The following options apply:
admin-state {enabled | disabled}—Specifies the administrative link sta te of the interface, whether
the interface is enabled or disabled.
Note
On all backplane sensing interfaces on all modules, admin-state is set to enabled and is
protected (you cannot change the setting). The admin-state has no effect (and is protected)
on the command and control interface. It only affects sensing interfaces. The command and
control interface does not need to be enabled because it cannot be monitored.
alt-tcp-reset-interface—Sends TCP resets out an alternate interface when this interface is used for
promiscuous monitoring and the reset action is triggered by a signature firing .
Note
You can only assign a sensing interface as an alternate TCP reset interface. You cannot
configure the management interface as an alternate TCP reset interface.
Note
There is only one sensing interface on the ASA IPS modules (ASA 5500-X IPS SSP and
ASA 5585-X IPS SSP), so you cannot designate an alternate TCP reset interface.
interface_name—Specifies the name of the interface on which TCP resets should be sent when
this interface is used for promiscuous monitoring and the reset action is triggered by a signature
firing. This setting is ignored when this interface is a member of an inline interface.
none —Disables the use of an alternate TCP reset interface. TCP resets triggered by the reset
action when in promiscuous mode will be sent out of this interface instead.
default—Sets the value back to the system default setting.
description—Specifies your description of the promiscuous interface.