22-6
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 22 Managing the AIP SSM and CSC SSM
Managing the AIP SSM
Configuring the Security Policy on the AIP SSM
On the AIP SSM, to configure the inspection and protection policy, which determines how to inspect
traffic and what to do when an intrusion is detected, perform the following steps. To session from the
security appliance to the AIP SSM, see the
“Sessioning to the AIP SSM” section on page 22-5
.
Step 1
To run the setup utility for initial configuration of the AIP SSM, enter the following command:
sensor#
setup
Step 2
Configure the IPS security policy. If you configure virtual sensors in IPS Version 6.0 or above, you
identify one of the sensors as the default. If the ASA 5500 series adaptive security appliance does not
specify a virtual sensor name in its configuration, the default sensor is used.
Because the IPS software that runs on the AIP SSM is beyond the scope of this document, detailed
configuration information is available in the following documents:
•
Configuring the Cisco Intrusion Prevention System Sensor Using the Command Line Interface
•
Command Reference for Cisco Intrusion Prevention System
Step 3
When you are done configuring the AIP SSM, exit the IPS software by entering the following command:
sensor#
exit
If you sessioned to the AIP SSM from the security appliance, you return to the security appliance
prompt.
Assigning Virtual Sensors to Security Contexts
If the security appliance is in multiple context mode, then you can assign one or more IPS virtual sensors
to each context. Then, when you configure the context to send traffic to the AIP SSM, you can specify
a sensor that is assigned to the context; you cannot specify a sensor that you did not assign to the context.
If you do not assign any sensors to a context, then the default sensor configured on the AIP SSM is used.
You can assign the same sensor to multiple contexts.
Note
You do not need to be in multiple context mode to use virtual sensors; you can be in single mode and use
different sensors for different traffic flows.
To assign one or more sensors to a security context, perform the following steps:
Step 1
To enter context configuration mode, enter the following command in the system execution space:
hostname(config)#
context
name
hostname(config-ctx)#
For more information about configuring contexts, see the
“Configuring a Security Context” section on
page 6-7
.
Step 2
To assign a virtual sensor to the context, enter the following command:
hostname(config-ctx)#
allocate-ips
sensor_name
[
mapped_name
] [
default
]
Enter this command for each sensor you want to assign to the context.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......