Download Print this page

Cisco ASA 5506-X Configuration Manual page 376

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Licensing Requirements for the ASA CX Module
Licensing Requirements for the ASA CX Module
The ASA CX module and PRSM require additional licenses, which need to be installed in the module
itself rather than in the context of the ASA. The ASA itself requires no additional licenses. See the ASA
CX documentation for more information.
Prerequisites for ASA CX
To use PRSM to configure the ASA, you need to install a certificate on the ASA for secure
communications. By default, the ASA generates a self-signed certificate. However, this certificate can
cause browser prompts asking you to verify the certificate because the publisher is unknown. To avoid
these browser prompts, you can instead install a certificate from a known certificate authority (CA). If
you request a certificate from a CA, be sure the certificate type is both a server authentication certificate
and a client authentication certificate. See the general operations configuration guide for more
information.
Guidelines for ASA CX
Context Mode Guidelines
Starting with ASA CX 9.1(3), multiple context mode is supported.
However, the ASA CX module itself (configured in PRSM) is a single context mode device; the
context-specific traffic coming from the ASA is checked against the common ASA CX policy. Therefore,
you cannot use the same IP addresses in multiple contexts; each context must include unique networks.
Firewall Mode Guidelines
Supported in routed and transparent firewall mode. Traffic-forwarding interfaces are only supported in
transparent mode.
Failover Guidelines
Does not support failover directly; when the ASA fails over, any existing ASA CX flows are transferred
to the new ASA, but the traffic is allowed through the ASA without being inspected by the ASA CX.
Only new flows received by the new ASA are acted upon by the ASA CX module.
ASA Clustering Guidelines
Does not support clustering.
IPv6 Guidelines
Model Guidelines
Cisco ASA Series Firewall CLI Configuration Guide
17-6
Supports IPv6.
(9.1(1) and earlier) Does not support NAT 64. In 9.1(2) and later, NAT 64 is supported.
Supported only on the ASA 5585-X and 5512-X through ASA 5555-X. See the Cisco ASA
Compatibility Matrix for more information:
http://www.cisco.com/en/US/docs/security/asa/compatibility/asamatrx.html
Chapter 17
ASA CX Module

Hide quick links:

Advertisement

loading