Chapter 13 Configuring the AIP SSM
Configuring the AIP SSM
13-8
Cisco ASA 5500 Series Getting Started Guide
78-19186-01
There is no license key installed on the system.
Please go to http://www.cisco.com/go/license
to obtain a new license or install a license.
AIP SSM#
Note
If you see the preceding license notice (which displays only in some versions of
software), you can ignore the message until you need to upgrade the signature
files on the AIP SSM. The AIP SSM continues to operate at the current signature
level until a valid license key is installed. You can install the license key at a later
time. The license key does not affect the current functionality of the AIP SSM.
Configuring the Security Policy on the AIP SSM
On the AIP SSM, to configure the inspection and protection policy, which
determines how to inspect traffic and what to do when an intrusion is detected,
perform the following steps. To session from the adaptive security appliance to the
AIP SSM, see the
“Sessioning to the AIP SSM” section on page 13-6
.
To configure the security policy on the AIP SSM, perform the following steps:
Step 1
To run the setup utility for initial configuration of the AIP SSM, enter the
following command:
sensor#
setup
Step 2
Configure the IPS security policy. If you configure virtual sensors in IPS Version
6.0 or above, you identify one of the sensors as the default. If the ASA 5500 series
adaptive adaptive security appliance does not specify a virtual sensor name in its
configuration, the default sensor is used.
Because the IPS software that runs on the AIP SSM is beyond the scope of this
document, detailed configuration information is available in the following
documents:
•
Configuring the Cisco Intrusion Prevention System Sensor Using the
Command Line Interface
•
Command Reference for Cisco Intrusion Prevention System