Download Print this page

Cisco ASA 5506-X Configuration Manual page 396

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

History for the ASA CX Module
History for the ASA CX Module
Feature Name
ASA 5585-X with SSP-10 and -20 support for
the ASA CX SSP-10 and -20
ASA 5512-X through ASA 5555-X support for
the ASA CX SSP
Monitor-only mode for demonstration
purposes
Cisco ASA Series Firewall CLI Configuration Guide
17-26
Platform
Releases
Description
ASA 8.4(4.1)
The ASA CX module lets you enforce security based on the
ASA CX 9.0(1)
complete context of a situation. This context includes the
identity of the user (who), the application or website that the
user is trying to access (what), the origin of the access
attempt (where), the time of the attempted access (when),
and the properties of the device used for the access (how).
With the ASA CX module, you can extract the full context
of a flow and enforce granular policies such as permitting
access to Facebook but denying access to games on
Facebook or permitting finance employees access to a
sensitive enterprise database but denying the same access to
other employees.
We introduced or modified the following commands:
capture, cxsc, cxsc auth-proxy, debug cxsc, hw-module
module password-reset, hw-module module reload,
hw-module module reset, hw-module module shutdown,
session do setup host ip, session do get-config, session do
password-reset, show asp table classify domain cxsc,
show asp table classify domain cxsc-auth-proxy, show
capture, show conn, show module, show service-policy.
ASA 9.1(1)
We introduced support for the ASA CX SSP software
ASA CX 9.1(1)
module for the ASA 5512-X, ASA 5515-X, ASA 5525-X,
ASA 5545-X, and ASA 5555-X.
We modified the following commands: session cxsc, show
module cxsc, sw-module cxsc.
ASA 9.1(2)
For demonstration purposes only, you can enable
ASA CX 9.1(2)
monitor-only mode for the service policy, which forwards a
copy of traffic to the ASA CX module, while the original
traffic remains unaffected.
Another option for demonstration purposes is to configure a
traffic-forwarding interface instead of a service policy in
monitor-only mode. The traffic-forwarding interface sends
all traffic directly to the ASA CX module, bypassing the
ASA.
We modified or introduced the following commands: cxsc
{fail-close | fail-open} monitor-only, traffic-forward
cxsc monitor-only.
Chapter 17
ASA CX Module

Hide quick links:

Advertisement

loading