![Cisco ASA 5512-X Скачать руководство пользователя страница 357](http://html.mh-extra.com/html/cisco/asa-5512-x/asa-5512-x_configuration-manual_63717357.webp)
16-17
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 16 ASA FirePOWER (SFR) Module
Configure the ASA FirePOWER Module
Procedure
Step 1
Do one of the following:
•
(All models.) Use SSH to connect to the ASA FirePOWER management IP address.
•
(Software modules only.) Open a session to the module from the ASA CLI (see the “Getting Started”
chapter in the general operations configuration guide to access the ASA CLI). In multiple context
mode, session from the system execution space.
hostname#
session sfr
Step 2
Log in with the username
admin
or another username that has the CLI configuration (Administrator)
access level.
Step 3
At the prompt, register the device to a FireSIGHT Management Center using the
configure manager
add
command, which has the following syntax:
configure manager add
{
hostname
|
IPv4_address
|
IPv6_address
|
DONTRESOLVE
}
reg_key
[
nat_id
]
where:
•
{
hostname
|
IPv4_address
|
IPv6_address
|
DONTRESOLVE
} specifies either the fully qualified
host name or IP address of the FireSIGHT Management Center. If the FireSIGHT Management
Center is not directly addressable, use DONTRESOLVE.
•
reg_key
is the unique alphanumeric registration key required to register a device to the FireSIGHT
Management Center.
•
nat_id
is an optional alphanumeric string used during the registration process between the
FireSIGHT Management Center and the device. It is required if the hostname is set to
DONTRESOLVE.
Step 4
Log into the FireSIGHT Management Center using an HTTPS connection in a browser, using the
hostname or address entered above. For example, https://DC.example.com.
Use the Device Management (
Devices > Device Management
) page to add the device. For more
information, see the online help or the Managing Devices chapter in the
FireSIGHT System User Guide
.
Configure the Security Policy on the ASA FirePOWER Module
The security policy controls the services provided by the module, such as Next Generation IPS filtering
and application filtering.
You use FireSIGHT Management Center to configure the security policy on the module.
For the ASA 5506-X, you can alternatively use ASDM. However, you can never use both ASDM and
FireSIGHT Management Center, you must choose one or the other. If you configure a FireSIGHT
Management Center for the module, you must use the configured manager. If you do not configure a
manager, you must use ASDM.
There is no CLI for configuring the security policy.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...