Intrusion Prevention
Intrusion Prevention

idp HA with Bypass

01.29.12   |  
‎01-29-2012 04:35 AM


I have two EXTERNAL ISG2000 configured in HA(active -passive), which is also connetted to cisco 6500 core switches in VSYS mode (actice-passive) i have two IDP 800, which i want to insert between the isg2000 and cisco core in HA. Is it possible to configure two ports on the ACM (VR1) and any failure the IDP'S should bypass traffic.


Also another VR2 for traffic between untrust (firewall) and DMZ Switch




Intrusion Prevention

Re: idp HA with Bypass

01.30.12   |  
‎01-30-2012 02:54 PM

IDP OS Release 5.1 supports high availability in network designs where you have deployed redundant network paths and use the failure detection features of a firewall, router, or switch to manage the cutover from the primary path to the backup path in cases of failure. Please see the following example:


We encourage you to provide feedback, comments, and suggestions so that we can improve the documentation. You can send your comments to, or fill out the documentation feedback form.


Thank you.

Juniper Networks
Technical Publications