skip to content

When an inline IPS reboots at a single-box branch, what does its bypass relay do, and what does that cost against an intruder?

level: juniorimportance: must knowfreq 58%

answer

  1. the box is the wire
  2. contacts close when the engine dies
  3. availability bought with inspection
  4. posture chosen before the window, not during
  5. the relay logs nothing

basics

~20 s

A hardware bypass relay shorts the two inline ports together when the engine stops, so the branch link keeps carrying packets. You buy availability with inspection: everything in that window, an intruder's traffic included, crosses unjudged.

solid answer

~50 s

An inline IPS sits in the wire, so if the box stops, the wire stops. A hardware bypass relay is a set of contacts that closes when the engine loses power or misses its watchdog heartbeat, welding the two ports together so packets pass end to end with no inspection. At a branch with one box and nobody on site, that relay is the only redundancy in the design, and the posture is decided in advance: fail-open keeps the branch online and unprotected for the reboot; fail-closed leaves the link down until the box returns. Either way the window is real -- tens of seconds for a reboot, minutes for a firmware upgrade -- and traffic inside it is never examined, including a session an intruder already has open. Know which posture each branch is wired for, how long the window really is, and what you will say crossed during it.

go deeper

for a junior

Be ready to say what inline means: the box sits in the wire, so its failure is the link's failure. Know that a hardware bypass relay closes the circuit so packets keep moving with no inspection at all.

for a middle

Explain the trigger -- lost power or a missed watchdog heartbeat -- and that the relay is physical, so the posture is a wiring and configuration choice made before the window rather than a decision taken during it.

for a senior

Show that you size the window against real session lifetimes, pick the posture per branch from what that branch carries, and can state afterwards what crossed unjudged and from which records.

for a principal

Own the trade the estate is buying: which sites may go dark, who signs for a fail-open window, and what an unattended branch costs when a relay does not restore and someone has to drive there.

## Inline means the box is the wire A passive sensor gets a copy of traffic and can only complain. An inline IPS is spliced into the path: packets enter one port, are evaluated, and leave the other. That is what lets it drop a packet rather than describe it afterwards, and it is also why its failure is not a monitoring gap but a link failure. A branch office on consumer broadband, with one box, no redundant pair and no local hands, has no second path to fall back to. ## What the bypass relay actually is On most inline appliances the two inline ports are wired through a physical relay. Under normal operation the contacts are open and each port terminates on the engine. When the engine stops -- power loss, a panic, or a watchdog heartbeat that stops arriving -- the contacts close and the two ports are connected directly to each other. Copper to copper (or an optical equivalent), no software involved. The two facts that matter: - It is **physical**, so it works precisely when the software does not. You cannot decide the posture during the outage; you decided it when the box was installed and configured. - It is **blind**. The relay has no visibility, no counters of its own and no log. Nothing records what crossed while it was closed. Some boxes also expose a *software* bypass -- the engine is running but told to forward without inspecting, typically to survive overload. That is a different mechanism with the same visible symptom, and both leave the same hole. ## Fail-open and fail-closed, wired per branch The relay can be configured either way, and at a single-box branch the choice is not abstract: | Posture | During a reboot | What you pay | |---|---|---| | Fail-open (relay closes) | Branch keeps working | Every packet crosses uninspected | | Fail-closed (relay stays open) | Branch link is down | The branch cannot trade until the box boots | The right answer differs by what the branch carries. A site whose traffic is guest wifi and web browsing can be dark for four minutes at 02:00; a site running card payments may not, or may be the one site you least want unjudged. That is a per-branch decision, and somebody at the branch has to accept whichever way it goes. ## Link state is part of the decision A related mechanism is link-state propagation: if one side of the inline pair loses link, the box drops the other side too. Without it, an upstream router keeps seeing a healthy interface and keeps sending traffic into a box that cannot forward -- a black hole that looks fine from both ends. With it, the failure is visible and any WAN failover that exists can react. At a single-WAN branch there is nothing to fail over to, so the value is simply that the branch knows it is down instead of silently blackholing. ## What the window costs you against an intruder Two distinct exposures live in a scheduled window: 1. **New traffic crosses unjudged.** Nothing evaluates it, so nothing drops it and nothing records it at the engine. If your rules would have caught an exploit attempt or a callback, they do not, and no alert is ever raised. 2. **Existing sessions survive.** A connection opened before the window keeps flowing through the closed relay and is still open when the engine returns -- at which point the engine has no handshake and no reassembly state for it and must decide whether to adopt it blind or cut it. The honest framing for an interview is that a maintenance window is a small, announced, repeated hole in a control you otherwise trust, and the point is not to pretend it is not there but to bound it: know its length, know its posture, know what still records during it. ## What still records The engine records nothing while it is stopped, so the accounting comes from upstream: router or WAN flow records (a five-tuple, packet and byte counts, timestamps -- and no payload at all), DNS resolver logs, proxy logs if the branch is proxied. Those let you say that bytes moved between these addresses at these times; they never let you say what those bytes were. That distinction is exactly what you will be asked for afterwards. ## The failure nobody plans for The relay can also fail to restore -- it latches closed, or the box never comes back and the branch is left running on bare copper. With no local hands, the fix is a courier or a van, and that cost belongs in the plan before the window opens, not after. The corresponding discipline is to verify positively after every window that the box is back in path and inspecting, rather than concluding from a quiet alert feed that all is well.

  • Why propagate link state to both sides instead of letting the box hold its interfaces up while it dies?
    If the box keeps both interfaces up while it cannot forward, upstream routing keeps pointing traffic into a black hole that looks healthy from every direction. Propagating the failure drops the partner interface so routing, or any WAN failover that exists, reacts. At a single-WAN branch there is nothing to fail over to, so the value is that the outage is visible immediately rather than presenting as unexplained packet loss.
  • The branch relay is wired fail-open. What do you owe the business once the window closes?
    The exact start and end of the window, a plain statement that no traffic in it was inspected, what you can still reconstruct from upstream flow records -- addresses, ports, byte counts and times, never payload -- and whether any session that spanned the window is still open. What you must not offer is 'no alerts fired, so nothing happened': no rule was running to fire.
  • Does wiring the relay fail-closed make the branch safer?
    It converts a visibility gap into an outage, which is only safer if someone has agreed the branch may be dark and has priced that. It also makes every reboot an incident, and with no local hands a relay that stays open after the box should have returned is a van, not a ticket. Safer is the wrong word; the honest word is different.

A turnstile with a break-glass bar: when the power fails the arm swings away so the crowd keeps moving. Nobody is stopped, and nobody is counted.

saying these in an interview costs you the question

  • Says the IPS keeps inspecting while it reboots
  • Thinks bypass posture can be chosen during the outage
  • Reads no alerts in the window as nothing crossed
  • Calls fail-open safe because the link stayed up
  • Treats one branch box as a highly available design

context