Bypass mode of the Cisco IPS system
If an IPS problem or fault occurs, especially when IPS work in traversing mode, this will cause problems to the entire network, sometimes even catastrophic, therefore, you must define the processing behavior of data traffic when an IPS fault occurs, as shown in Figure 5.4. If an IPS fault occurs, the best solution is to pass the traffic directly, the Cisco IPS system provides three key options for bypass:
650) this. width = 650; "src =" http://www.bkjia.com/uploads/allimg/131227/0519493C7-0.png "title =" 1.png"/>
BypassKey options:
ÜAuto:Automatic mode, which is determined by three factors. When the link is down or up, It is bypass, when the traffic starts or stops, and when it reaches the parameters defined by traffic flow configurications, the default value is auto.
ÜOff:Disable the bypass function. All data traffic must be analyzed before it can be passed. Even if an IPS problem occurs, do not pass the data traffic. This is an extreme behavior, it is usually used in an environment with high traffic security detection. It is called "the essence is better than the whole ".
ÜOn:Enable the bypass function to indicate that no data streams are analyzed. You can directly use IPS, or directly use bypass.
This article is from the "unknown Christ" blog. For more information, contact the author!