18-2
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 18 ASA IPS Module
Information About the ASA IPS Module
How the ASA IPS Module Works with the ASA
The ASA IPS module runs a separate application from the ASA. The ASA IPS module might include an
external management interface so you can connect to the ASA IPS module directly; if it does not have a
management interface, you can connect to the ASA IPS module through the ASA interface. The ASA
IPS SSP on the ASA 5585-X includes data interfaces; these interfaces provide additional port-density
for the ASA. However, the overall through-put of the ASA is not increased.
Traffic goes through the firewall checks before being forwarded to the ASA IPS module. When you
identify traffic for IPS inspection on the ASA, traffic flows through the ASA and the ASA IPS module
as follows.
Note
: This example is for “inline mode.” See
for information
about “promiscuous mode,” where the ASA only sends a copy of the traffic to the ASA IPS module.
1.
Traffic enters the ASA.
2.
Incoming VPN traffic is decrypted.
3.
Firewall policies are applied.
4.
Traffic is sent to the ASA IPS module.
5.
The ASA IPS module applies its security policy to the traffic, and takes appropriate actions.
6.
Valid traffic is sent back to the ASA; the ASA IPS module might block some traffic according to its
security policy, and that traffic is not passed on.
7.
Outgoing VPN traffic is encrypted.
8.
Traffic exits the ASA.
shows the traffic flow when running the ASA IPS module in inline mode. In this example,
the ASA IPS module automatically blocks traffic that it identified as an attack. All other traffic is
forwarded through the ASA.
Figure 18-1
ASA IPS module Traffic Flow in the ASA: Inline Mode
Operating Modes
You can send traffic to the ASA IPS module using one of the following modes:
•
Inline mode—This mode places the ASA IPS module directly in the traffic flow (see
).
No traffic that you identified for IPS inspection can continue through the ASA without first passing
through, and being inspected by, the ASA IPS module. This mode is the most secure because every
A
S
A
Main
S
ystem
IP
S
Diverted Tr
a
ffic
IP
S
in
s
pection
VPN
Decryption
Firew
a
ll
Policy
Block
251
157
in
s
ide
o
u
t
s
ide
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...