4-17
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter4 Configuring Interfaces
Configuring Inline Interface Mode
Figure 4-2 illustrates inline interface pair mode:
Figure 4-2 Inline Interface Pair Mode
Configuring Inline Interface Pairs
Use the inline-interfaces name command in the service interface submode to create inline interface
pairs.
Note
You can configure the ASA IPS modules (ASA5500-X IPS SSP and ASA 5585-X IPS SSP) to operate
inline even though they have only one sensing interface.
The following options apply:
inline-interfaces name—Specifies the name of the logical inline interface pair.
default—Sets the value back to the system default setting.
description—Specifies your description of the inline interface pair.
interface1 interface_name—Specifies the first interface in the inline interface pair.
interface2 interface_name—Specifies the second interface in the inline interface pair.
no—Removes an entry or selection setting.
admin-state {enabled | disabled}—Specifies the administrative link sta te of the interface, whether
the interface is enabled or disabled.
Note
On all backplane sensing interfaces on all modules, admin-state is set to enabled and is
protected (you cannot change the setting). The admin-state has no effect (and is protected)
on the command and control interface. It only affects sensing interfaces. The command and
control interface does not need to be enabled because it cannot be monitored.
Creating Inline Interface Pairs
To create inline interface pairs, follow these steps:
Step 1
Log in to the CLI using an account with administrator privileges.
Step 2
Enter interface submode.
sensor# configure terminal
sensor(config)# service interface
sensor(config-int)#
Host
Sensor Switch
Traffic passes
through interface pair
253444
Router
VLAN A