Download Print this page

Cisco ASA 5506-X Configuration Manual page 405

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Chapter 18
ASA IPS Module
Session to the module. Access the IPS CLI over the backplane.See
Step 2
ASA, page
Step 3
(ASA 5512-X through ASA 5555-X; may be required) Install the software module. See
through ASA 5555-X) Booting the Software Module, page
Step 4
ASAConfigure basic network settings for the IPS module. See
Settings, page
On the module, configure the inspection and protection policy, which determines how to inspect traffic
Step 5
and what to do when an intrusion is detected. See
Module, page
(Optional) On the ASA in multiple context mode, specify which IPS virtual sensors are available for
Step 6
each context (if you configured virtual sensors). See
page
On the ASA, identify traffic to divert to the ASA IPS module. See
Step 7
module, page
Connecting the ASA IPS Management Interface
In addition to providing management access to the IPS module, the IPS management interface needs
access to an HTTP proxy server or a DNS server and the Internet so it can download global correlation,
signature updates, and license requests. This section describes recommended network configurations.
Your network may differ.
ASA 5585-X (Hardware Module)
The IPS module includes a separate management interface from the ASA.
ASA 5585-X
SSP
If you have an inside router
If you have an inside router, you can route between the management network, which can include both
the ASA Management 0/0 and IPS Management 1/0 interfaces, and the ASA inside network. Be sure to
also add a route on the ASA to reach the Management network through the inside router.
18-10.
18-11.
18-12.
18-13.
18-15.
ASA 5585-X (Hardware Module), page 18-7
ASA 5512-X through ASA 5555-X (Software Module), page 18-8
IPS SSP
SFP1
SFP0
7
6
5
4
SFP1
SFP0
7
6
5
4
Configuring the Security Policy on the ASA IPS
Assigning Virtual Sensors to a Security Context,
IPS Management 1/0
Default IP: 192.168.1.2
0
1
3
2
1
0
1
MGMT
0
USB
0
1
3
2
1
0
1
MGMT
0
USB
ASA Management 0/0
Default IP: 192.168.1.1
Cisco ASA Series Firewall CLI Configuration Guide
Configuring the ASA IPS module
Sessioning to the Module from the
18-10.
Configuring Basic IPS Module Network
Diverting Traffic to the ASA IPS
RESET
AUX
CONSOLE
RESET
AUX
CONSOLE
(ASA 5512-X
18-7

Hide quick links:

Advertisement

loading