18-15
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 18 ASA IPS Module
Configuring the ASA IPS module
Examples
The following example assigns sensor1 and sensor2 to context A, and sensor1 and sensor3 to context B.
Both contexts map the sensor names to “ips1” and “ips2.” In context A, sensor1 is set as the default
sensor, but in context B, no default is set so the default that is configured on the ASA IPS module is used.
hostname(config-ctx)#
context
A
hostname(config-ctx)#
allocate-interface gigabitethernet0/0.100 int1
hostname(config-ctx)#
allocate-interface gigabitethernet0/0.102 int2
hostname(config-ctx)#
allocate-interface gigabitethernet0/0.110-gigabitethernet0/0.115
int3-int8
hostname(config-ctx)#
allocate-ips sensor1 ips1 default
hostname(config-ctx)#
allocate-ips sensor2 ips2
hostname(config-ctx)#
config-url
ftp://user1:[email protected]/configlets/test.cfg
hostname(config-ctx)#
member gold
hostname(config-ctx)#
context
sample
hostname(config-ctx)#
allocate-interface gigabitethernet0/1.200 int1
hostname(config-ctx)#
allocate-interface gigabitethernet0/1.212 int2
hostname(config-ctx)#
allocate-interface gigabitethernet0/1.230-gigabitethernet0/1.235
int3-int8
hostname(config-ctx)#
allocate-ips sensor1 ips1
hostname(config-ctx)#
allocate-ips sensor3 ips2
hostname(config-ctx)#
config-url
ftp://user1:[email protected]/configlets/sample.cfg
hostname(config-ctx)#
member silver
hostname(config-ctx)#
changeto context A
...
What to Do Next
Change to each context to configure the IPS security policy as described in
.
Diverting Traffic to the ASA IPS module
This section identifies traffic to divert from the ASA to the ASA IPS module.
Prerequisites
In multiple context mode, perform these steps in each context execution space. To change to a context,
enter the
changeto context
context_name
command.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...