Cisco PIX 500 Series Configuration Manual page 421

Security appliance command line
Hide thumbs Also See for PIX 500 Series:
Table of Contents

Advertisement

Chapter 22
Managing the AIP SSM and CSC SSM
ASDM and the CSC SSM maintain separate passwords. You can configure their passwords to be
Note
identical; however, changing one of these two passwords does not affect the other password.
The connection between the host running ASDM and the adaptive security appliance is made through a
management port on the adaptive security appliance. The connection to the CSC SSM GUI is made
through the SSM management port. Because these two connections are required to manage the CSC
SSM, any host running ASDM must be able to reach the IP address of both the adaptive security
appliance management port and the SSM management port.
Figure 22-6
management network. While use of a dedicated management network is not required, we recommend it.
Of particular interest are the following:
An HTTP proxy server is connected to the inside network and to the management network. This
HTTP proxy server enables the CSC SSM to contact the Trend Micro update server.
The management port of the adaptive security appliance is connected to the management network.
To permit management of the adaptive security appliance and the CSC SSM, hosts running ASDM
must be connected to the management network.
The management network includes an SMTP server for e-mail notifications for the CSC SSM and a
syslog server to which the CSC SSM can send system log messages.
Figure 22-6
HTTP
Proxy
ASDM
Syslog
Notifications
SMTP Server
The CSC SSM cannot support Stateful Failover because the CSC SSM does not maintain connection
information, and therefore cannot provide the failover unit with the required information for Stateful
Failover. The connections that a CSC SSM is scanning are dropped when the security appliance in which
the CSC SSM is installed fails. When the standby adaptive security appliance becomes active, it will
forward the scanned traffic to the CSC SSM and the connections will be reset.
OL-12172-03
shows an adaptive security appliance with a CSC SSM that is connected to a dedicated
CSC SSM Deployment with a Management Network
Security
Appliance
inside
192.168.100.1
Main System
management port
192.168.50.1
CSC SSM
192.168.50.38 SSM
outside
Internet
10.6.13.67
management
port
Cisco Security Appliance Command Line Configuration Guide
Managing the CSC SSM
Trend Micro
Update Server
22-11

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5500 series

Table of Contents