22-2
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 22 Managing the AIP SSM and CSC SSM
Managing the AIP SSM
•
Using Virtual Sensors, page 22-3
•
AIP SSM Procedure Overview, page 22-4
How the AIP SSM Works with the Adaptive Security Appliance
The AIP SSM runs a separate application from the adaptive security appliance. It is, however, integrated
into the adaptive security appliance traffic flow. The AIP SSM does not contain any external interfaces
itself, other than a management interface. When you identify traffic for IPS inspection on the adaptive
security appliance, traffic flows through the adaptive security appliance and the AIP SSM in the
following way:
1.
Traffic enters the adaptive security appliance.
2.
Firewall policies are applied.
3.
Traffic is sent to the AIP SSM over the backplane.
See the
“Operating Modes” section on page 22-2
for information about only sending a copy of the
traffic to the AIP SSM.
4.
The AIP SSM applies its security policy to the traffic, and takes appropriate actions.
5.
Valid traffic is sent back to the adaptive security appliance over the backplane; the AIP SSM might
block some traffic according to its security policy, and that traffic is not passed on.
6.
VPN policies are applied (if configured).
7.
Traffic exits the adaptive security appliance.
Figure 22-1
shows the traffic flow when running the AIP SSM in inline mode. In this example, the AIP
SSM automatically blocks traffic that it identified as an attack. All other traffic is forwarded through the
security appliance.
Figure 22-1
AIP SSM Traffic Flow in the Adaptive Security Appliance: Inline Mode
Operating Modes
You can send traffic to the AIP SSM using one of the following modes:
•
Inline mode—This mode places the AIP SSM directly in the traffic flow (see
Figure 22-1
). No traffic
that you identified for IPS inspection can continue through the adaptive security appliance without
first passing through, and being inspected by, the AIP SSM. This mode is the most secure because
Security Appliance
Main System
inside
AIP SSM
Diverted Traffic
IPS inspection
outside
Backplane
VPN
Policy
Firewall
Policy
Block
191313
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......