VLAN Bridging with FirePOWER
Although not immediately obvious, the FirePOWER Series 3 devices can do a form of IPS on a stick. This means that the capability described here should be available to the current appliance versions of the FirePOWER managed devices. The premise involves connecting broadcast domains (VLANs) to bring the managed device inline between the initiator and responder of a flow. Configuration is fairly straightforward but does have some caveats.
Caveats
- Even though only a single port is required, a virtual switch must be configured (this cannot just be an inline pair)
- BPDUs being bridged between VLANs are detected and will render the switchport(s) in an inconsistent state
- The FirePOWER physical interface will not activate until it is also bound to a Virtual Switch
The diagram shows two devices in the same VLAN (we will assume /24 for the configuration). The device on the top is in VLAN 100. The FirePOWER managed device bridges VLAN 100 to VLAN 101 and allows the two devices to communicate directly with one another. The connection to the FirePOWER device is a single 802.1q trunk.
Frames arriving on VLAN 100 will be processed and egress with a VLAN tag of 101. This configuration is similar to a Continue reading
Optical giant split raises acquisition talk.
Giddy up, y'all -- It's roundup time!
Free booklet from Ixia describes detailed methodologies to verify SDN & OpenFlow functionality and performance so your network performs at the highest level.