17-7
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 17 ASA CX Module
Guidelines for ASA CX
•
For the 5512-X through ASA 5555-X, you must install a Cisco solid state drive (SSD). For more
information, see the ASA 5500-X hardware guide.
Monitor-Only Mode Guidelines
Monitor-only mode is strictly for demonstration purposes and is not a normal operational mode for the
module.
•
You cannot configure both monitor-only mode and normal inline mode at the same time on the ASA.
Only one type of security policy is allowed. In multiple context mode, you cannot configure
monitor-only mode for some contexts, and regular inline mode for others.
•
The following features are not supported in monitor-only mode:
–
Deny policies
–
Active authentication
–
Decryption policies
•
The ASA CX does not perform packet buffering in monitor-only mode, and events will be generated
on a best-effort basis. For example, some events, such as ones with long URLs spanning packet
boundaries, may be impacted by the lack of buffering.
•
Be sure to configure both the ASA policy and the ASA CX to have matching modes: both in
monitor-only mode, or both in normal inline mode.
Additional guidelines for traffic-forwarding interfaces:
•
The ASA must be in transparent mode.
•
You can configure up to 4 interfaces as traffic-forwarding interfaces. Other ASA interfaces can be
used as normal.
•
Traffic-forwarding interfaces must be physical interfaces, not VLANs or BVIs. The physical
interface also cannot have any VLANs associated with it.
•
Traffic-forwarding interfaces cannot be used for ASA traffic; you cannot name them or configure
them for ASA features, including failover or management-only.
•
You cannot configure both a traffic-forwarding interface and a service policy for ASA CX traffic.
Additional Guidelines and Limitations
•
See
Compatibility with ASA Features, page 17-5
.
•
You cannot change the software type installed on the hardware module; if you purchase an ASA CX
module, you cannot later install other software on it.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...