22-11
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 22 Managing the AIP SSM and CSC SSM
Managing the CSC SSM
Note
ASDM and the CSC SSM maintain separate passwords. You can configure their passwords to be
identical; however, changing one of these two passwords does not affect the other password.
The connection between the host running ASDM and the adaptive security appliance is made through a
management port on the adaptive security appliance. The connection to the CSC SSM GUI is made
through the SSM management port. Because these two connections are required to manage the CSC
SSM, any host running ASDM must be able to reach the IP address of both the adaptive security
appliance management port and the SSM management port.
Figure 22-6
shows an adaptive security appliance with a CSC SSM that is connected to a dedicated
management network. While use of a dedicated management network is not required, we recommend it.
Of particular interest are the following:
•
An HTTP proxy server is connected to the inside network and to the management network. This
HTTP proxy server enables the CSC SSM to contact the Trend Micro update server.
•
The management port of the adaptive security appliance is connected to the management network.
To permit management of the adaptive security appliance and the CSC SSM, hosts running ASDM
must be connected to the management network.
•
The management network includes an SMTP server for e-mail notifications for the CSC SSM and a
syslog server to which the CSC SSM can send system log messages.
Figure 22-6
CSC SSM Deployment with a Management Network
The CSC SSM cannot support Stateful Failover because the CSC SSM does not maintain connection
information, and therefore cannot provide the failover unit with the required information for Stateful
Failover. The connections that a CSC SSM is scanning are dropped when the security appliance in which
the CSC SSM is installed fails. When the standby adaptive security appliance becomes active, it will
forward the scanned traffic to the CSC SSM and the connections will be reset.
148387
192.168.100.1
192.168.50.1
Notifications
SMTP Server
192.168.50.38 SSM
management
port
10.6.13.67
Trend Micro
Update Server
Security
Appliance
Main System
inside
CSC SSM
outside
HTTP
Proxy
management port
ASDM
Syslog
Internet
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......