18-7
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 18 ASA IPS Module
Configuring the ASA IPS module
Step 2
Session to the module. Access the IPS CLI over the backplane.See
Sessioning to the Module from the
Step 3
(ASA 5512-X through ASA 5555-X; may be required) Install the software module. See
through ASA 5555-X) Booting the Software Module, page 18-10
.
Step 4
ASAConfigure basic network settings for the IPS module. See
Configuring Basic IPS Module Network
Step 5
On the module, configure the inspection and protection policy, which determines how to inspect traffic
and what to do when an intrusion is detected. See
Configuring the Security Policy on the ASA IPS
Step 6
(Optional) On the ASA in multiple context mode, specify which IPS virtual sensors are available for
each context (if you configured virtual sensors). See
Assigning Virtual Sensors to a Security Context,
.
Step 7
On the ASA, identify traffic to divert to the ASA IPS module. See
Diverting Traffic to the ASA IPS
Connecting the ASA IPS Management Interface
In addition to providing management access to the IPS module, the IPS management interface needs
access to an HTTP proxy server or a DNS server and the Internet so it can download global correlation,
signature updates, and license requests. This section describes recommended network configurations.
Your network may differ.
•
ASA 5585-X (Hardware Module), page 18-7
•
ASA 5512-X through ASA 5555-X (Software Module), page 18-8
ASA 5585-X (Hardware Module)
The IPS module includes a separate management interface from the ASA.
If you have an inside router
If you have an inside router, you can route between the management network, which can include both
the ASA Management 0/0 and IPS Management 1/0 interfaces, and the ASA inside network. Be sure to
also add a route on the ASA to reach the Management network through the inside router.
ASA 5585-X
PWR
BOO
T
ALARM AC
T
VPN
PS1
HDD1
PS0
HDD0
USB
RESET
0
SFP1
SFP0
1
0
1
2
3
4
5
6
7
MGMT
0
1
AUX
CONSOLE
PWR
BOO
T
ALARM AC
T
VPN
PS1
HDD1
PS0
HDD0
USB
RESET
0
SFP1
SFP0
1
0
1
2
3
4
5
6
7
MGMT
0
1
AUX
CONSOLE
ASA Management 0/0
Default IP: 192.168.1.1
IPS Management 1/0
Default IP: 192.168.1.2
SSP
IPS SSP
334656
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...