Intrusion Prevention
Reply
Contributor
speedpill
Posts: 42
Registered: ‎07-20-2010
0

Transparent Inline mode - VLAN Question

Hello Everyone,

 

I am going to be implementing an HA Juniper IPS appiiance using inline Transparent mode.

 

This is my diagram..

 

 

                         SWITCH 1   -----------------  SWITCH 2

                               |                                    |

                               |                                    |

                               |                                    |

                               |                                    |

 

                          Juniper IPS                    Juniper IPS

                                |                                   |

                                |                                   |

                                |                                   |

                                |                                   |

------------------------------------------------------------------

|                                                                                      |

|                         CISCO SWITCH                                |---------------------Standby CISCO SWITCH

|                                                                                      |                                        |

------------------------------------------------------------------                                SERVER FARMS

                                          |

                              SERVER FARMS

 

 

If there are multiple vlans on the switch connecting to the server farms, then the interface connecting the Juniper IPS to the CISCO SWITCH, will be like a mirrored port getting packets from all vlans in all interfaces. Otherwise how else will the IPS get packets from all the servers?

 

Thanks

 

 

Recognized Expert
aweck
Posts: 255
Registered: ‎07-24-2009
0

Re: Transparent Inline mode - VLAN Question

Traffic will be controled by spanning tree on the switches.  The switches should just act they are directly connected with no IDP's in-between, forwarding layer-2 packets per their broadcast domain & repsective CAM tables.

Juniper Elite Partner
JNCIE-ENT #63, JNCIE-SP #705, JNCIE-SEC #17, JNCIS-FWV, JNCIS-SSL
Contributor
DaveS
Posts: 21
Registered: ‎06-12-2009
0

Re: Transparent Inline mode - VLAN Question

I have the exact same set up as your diagram with Cisco switch;s. I had a lot of spanning tree issues at first.. I built a etherchannell between the switch's and that resolved all it.

Contributor
speedpill
Posts: 42
Registered: ‎07-20-2010
0

Re: Transparent Inline mode - VLAN Question

Hello Dave,

 

Could you tell me how you made the etherchannel between the switches? How did that stop all your spanning tree issues?

 

A quick response would be greatly appreciated.

 

Thanks

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.