22-3
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 22 Managing the AIP SSM and CSC SSM
Managing the AIP SSM
every packet that you identify for inspection is analyzed before being allowed through. Also, the AIP
SSM can implement a blocking policy on a packet-by-packet basis. This mode, however, can affect
throughput.
•
Promiscuous mode—This mode sends a duplicate stream of traffic to the AIP SSM. This mode is
less secure, but has little impact on traffic throughput. Unlike the inline mode, in promiscuous mode
the AIP SSM can only block traffic by instructing the adaptive security appliance to shun the traffic
or by resetting a connection on the adaptive security appliance. Also, while the AIP SSM is
analyzing the traffic, a small amount of traffic might pass through the adaptive security appliance
before the AIP SSM can shun it.
Figure 22-2
shows the AIP SSM in promiscuous mode. In this
example, the AIP SSM sends a shun message to the security appliance for traffic it identified as a
threat.
Figure 22-2
AIP SSM Traffic Flow in the Adaptive Security Appliance: Promiscuous Mode
Using Virtual Sensors
The AIP SSM running IPS software Version 6.0 and above can run multiple virtual sensors, which means
you can configure multiple security policies on the AIP SSM. You can assign each context or single
mode security appliance to one or more virtual sensors, or you can assign multiple security contexts to
the same virtual sensor. See the IPS documentation for more information about virtual sensors, including
the maximum number of sensors supported.
Figure 22-3
shows one security context paired with one virtual sensor (in inline mode), while two
security contexts share the same virtual sensor.
Security Appliance
Main System
inside
AIP SSM
IPS inspection
outside
Backplane
VPN
Policy
Firewall
Policy
Shun
message
191314
Copied Traffic
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......