17-26
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 17 ASA CX Module
History for the ASA CX Module
History for the ASA CX Module
Feature Name
Platform
Releases
Description
ASA 5585-X with SSP-10 and -20 support for
the ASA CX SSP-10 and -20
ASA 8.4(4.1)
ASA CX 9.0(1)
The ASA CX module lets you enforce security based on the
complete context of a situation. This context includes the
identity of the user (who), the application or website that the
user is trying to access (what), the origin of the access
attempt (where), the time of the attempted access (when),
and the properties of the device used for the access (how).
With the ASA CX module, you can extract the full context
of a flow and enforce granular policies such as permitting
access to Facebook but denying access to games on
Facebook or permitting finance employees access to a
sensitive enterprise database but denying the same access to
other employees.
We introduced or modified the following commands:
capture
,
cxsc
,
cxsc auth-proxy
,
debug cxsc
,
hw-module
module password-reset
,
hw-module module reload
,
hw-module module reset
,
hw-module module shutdown
,
session do setup host ip, session do get-config, session do
password-reset, show asp table classify domain cxsc
,
show asp table classify domain cxsc-auth-proxy
,
show
capture
,
show conn
,
show module
,
show service-policy
.
ASA 5512-X through ASA 5555-X support for
the ASA CX SSP
ASA 9.1(1)
ASA CX 9.1(1)
We introduced support for the ASA CX SSP software
module for the ASA 5512-X, ASA 5515-X, ASA 5525-X,
ASA 5545-X, and ASA 5555-X.
We modified the following commands:
session cxsc
,
show
module cxsc
,
sw-module cxsc
.
Monitor-only mode for demonstration
purposes
ASA 9.1(2)
ASA CX 9.1(2)
For demonstration purposes only, you can enable
monitor-only mode for the service policy, which forwards a
copy of traffic to the ASA CX module, while the original
traffic remains unaffected.
Another option for demonstration purposes is to configure a
traffic-forwarding interface instead of a service policy in
monitor-only mode. The traffic-forwarding interface sends
all traffic directly to the ASA CX module, bypassing the
ASA.
We modified or introduced the following commands:
cxsc
{
fail-close
|
fail-open
}
monitor-only
,
traffic-forward
cxsc monitor-only
.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...