18-9
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 18 ASA IPS Module
Configuring the ASA IPS module
If you have an inside router
If you have an inside router, you can route between the Management 0/0 network, which includes both
the ASA and IPS management IP addresses, and the inside network. Be sure to also add a route on the
ASA to reach the Management network through the inside router.
If you do not have an inside router
If you have only one inside network, then you cannot also have a separate management network. In this
case, you can manage the ASA from the inside interface instead of the Management 0/0 interface. If you
remove the ASA-configured name from the Management 0/0 interface, you can still configure the IPS
IP address for that interface. Because the IPS module is essentially a separate device from the ASA, you
can
configure the IPS management address to be on the same network as the inside interface.
Note
You must remove the ASA-configured name for Management 0/0; if it is configured on the ASA, then
the IPS address must be on the same network as the ASA, and that excludes any networks already
configured on other ASA interfaces. If the name is not configured, then the IPS address can be on any
network, for example, the ASA inside network.
What to Do Next
•
Configure basic network settings. See
Configuring Basic IPS Module Network Settings, page 18-11
Internet
Management PC
Proxy or DNS Server (for example)
Router
ASA
Management 0/0
Outside
IPS
Management
Inside
IPS Default
Gateway
ASA gateway for Management
334667
Internet
Management PC
Layer 2
Switch
ASA
Inside
Management 0/0
(IPS only)
Outside
IPS
IPS Default Gateway
Proxy or DNS Server
(for example)
334669
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...