Duplicate Packet?

Hi all,

I have some questions about Duplicate Packets:

  1. How mcafee IPS treats the duplicate Packets? Does it still scan the duplicate packets or just forward without inspection?
  2. Which packets is considered as duplicate packets? The same (source MAC, Destination MAC), same (source IP, destination IP), same (source port, destination port), same sequence number, etc...
  3. Assume that we have the network like this:
    • Link between SW01 and R1 is configured as trunk
    • McAfee IPS sits between SW01 and R1.
    • We have 3 vlan
    • Traffic from PC1 to PC2 will first hit IPS, received by R1. R1 does routing and forwards this packet to back. This packet will hit the IPS again with the same data from Layer 3 to Layer 7, but the Layer 2 header is changed. So is this packet considered as duplicate packet?
    • What's the best practice for this case? Because if the IPS inspect the same traffic twice, the performance is decreased, duplicate alerts will occur.

Duplicate Packet.png


