In a passive IPS deployment for a Cisco Secure Firewall Threat Defense (FTD) device, the administrator must configure the interface to operate in passive mode. This involves setting the interface mode, associating it with a security zone, enabling the interface, and setting the MTU parameter.
Steps:
Set the interface mode to passive:
In FMC, navigate toDevices > Device Management.
Select the FTD device and configure the relevant interface.
Set the interface mode to " Passive. "
Associate the interface with a security zone:
Create or select an appropriate security zone.
Assign the passive interface to this security zone.
Enable the interface:
Ensure the interface is enabled to receive traffic.
Set the MTU parameter:
Configure the Maximum Transmission Unit (MTU) parameter as required.
This ensures that the FTD device can inspect traffic passively without impacting the network flow.
[References:Cisco Secure Firewall Management Center Device Configuration Guide, Chapter on Interface Settings, , , , , ]
Submit