22-18
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 22 Managing the AIP SSM and CSC SSM
Checking SSM Status
hostname(config-cmap)#
match access-list csc_in
hostname
policy-map csc_in_policy
hostname(config-pmap)#
class csc_inbound_class
hostname(config-pmap-c)#
csc fail-close
hostname
service-policy csc_in_policy interface outside
Note
FTP inspection must be enabled for the CSC SSM to scan files transferred by FTP. FTP inspection is
enabled by default.
Checking SSM Status
To check the status of an SSM, use the
show module
command.
The following is sample output from the
show module
command on an adaptive security appliance with
a CSC SSM installed. The Status field indicates the operational status of the SSM. An SSM operating
normally has a status of “Up” in the output of the
show module
command. While the adaptive security
appliance transfers an application image to the SSM, the Status field in the output reads “Recover.” For
more information about possible statuses, see the entry for the
show module
command in the
Cisco
Security Appliance Command Reference
.
hostname#
show module 1
Mod Card Type Model Serial No.
--- -------------------------------------------- ------------------ -----------
0 ASA 5520 Adaptive Security Appliance ASA5520 P3000000034
1 ASA 5500 Series Security Services Module-20 ASA-SSM-20 0
Mod MAC Address Range Hw Version Fw Version Sw Version
--- --------------------------------- ------------ ------------ ---------------
0 000b.fcf8.c30d to 000b.fcf8.c311 1.0 1.0(10)0 7.1(0)1
1 000b.fcf8.012c to 000b.fcf8.012c 1.0 1.0(10)0 Trend Micro InterScan Security Module Version 5.0
Mod SSM Application Name SSM Application Version
--- ------------------------------ --------------------------
1 Trend Micro InterScan Security Version 5.0
Mod Status Data Plane Status Compatibility
--- ------------------ --------------------- -------------
0 Up Sys Not Applicable
1 Up Up
The argument
1
, at the end of the command, is the slot number occupied by the SSM. If you do not know
the slot number, you can omit it and see information about all modules, including the adaptive security
appliance, which is considered to occupy slot 0 (zero).
Use the
details
keyword to view additional information for the SSM.
The following is sample output from the
show module details
command on an adaptive security
appliance with a CSC SSM installed.
hostname#
show module 1 details
Getting details from the Service Module, please wait...
ASA 5500 Series Security Services Module-20
Model: ASA-SSM-20
Hardware version: 1.0
Serial Number: 0
Firmware version: 1.0(10)0
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......