1-21
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the ASA IPS Module
Managing the ASA IPS module
Managing the ASA IPS module
This section includes procedures that help you recover or troubleshoot the module and includes the
following topics:
•
Installing and Booting an Image on the Module, page 1-21
•
Shutting Down the Module, page 1-23
•
Uninstalling a Software Module Image, page 1-23
•
Resetting the Password, page 1-23
•
Reloading or Resetting the Module, page 1-24
Installing and Booting an Image on the Module
If the module suffers a failure, and the module application image cannot run, you can reinstall a new
image on the module from a TFTP server (for a physical module), or from the local disk (software
module).
Note
Do not use the
upgrade
command within the module software to install the image.
Prerequisites
•
Physical module—Be sure the TFTP server that you specify can transfer files up to 60 MB in size.
Note
This process can take approximately 15 minutes to complete, depending on your network
and the size of the image.
•
Software module—Copy the image to the ASA internal flash (disk0) before completing this
procedure.
Step 7
(Optional)
ips
{
inline
|
promiscuous
} {
fail-close
|
fail-open
} [
sensor
{
sensor_name
|
mapped_name
}]
Example:
hostname(config-pmap-c)# ips promiscuous
fail-close
Specifies that the second class of traffic should be sent to the ASA
IPS module.
Add as many classes as desired by repeating these steps.
Step 8
service-policy
policymap_name
{
global
|
interface
interface_name
}
Example:
hostname(config)# service-policy
tcp_bypass_policy outside
Activates the policy map on one or more interfaces.
global
applies
the policy map to all interfaces, and
interface
applies the policy
to one interface. Only one global policy is allowed. You can
override the global policy on an interface by applying a service
policy to that interface. You can only apply one policy map to
each interface.
Command
Purpose
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......