30-33
Cisco ASA Series Firewall CLI Configuration Guide
Chapter30 Configuring the ASA CX Module
Feature History for the ASA CX Module
ciscoasa(config-pmap)# class my-cx-class2
ciscoasa(config-pmap-c)# cxsc fail-open auth-proxy
ciscoasa(config-pmap-c)# service-policy my-cx-policy interface outside
Feature History for the ASA CX Module
Table30-2 lists each feature change and the platform release in which it was implemented.
Table30-2 Feature History for the ASA CX Module
Feature Name
Platform
Releases Feature Information
ASA 5585-X with SSP-10 and -20 support for
the ASA CX SSP-10 and -20
ASA 8.4(4.1)
ASA CX 9.0(1)
The ASA CX module lets you enforce security based on the
complete context of a situation. This context includes the
identity of the user (who), the application or website that the
user is trying to access (what), the origin of the access
attempt (where), the time of the attempted access (when),
and the properties of the device used for the access (how).
With the ASA CX module, you can extract the full context
of a flow and enforce granular policies such as permitting
access to Facebook but denying access to games on
Facebook or permitting finance employees access to a
sensitive enterprise database but denying the same access to
other employees.
We introduced or modified the following commands:
capture, cxsc, cxsc auth-proxy, debug cxsc, hw-module
module password-reset, hw-module module reload,
hw-module module reset, hw-module module shutdown,
session do setup host ip, session do get-config, session do
password-reset, show asp table classify domain cxsc,
show asp table classify domain cxsc-auth-proxy, show
capture, show conn, show module, show service-policy.
ASA 5512-X through ASA 5555-X support for
the ASA CX SSP
ASA 9.1(1)
ASA CX 9.1(1)
We introduced support for the ASA CX SSP software
module for the ASA 5512-X, ASA 5515-X, ASA 5525-X,
ASA 5545-X, and ASA 5555-X.
We modified the following commands: session cxsc, show
module cxsc, sw-module cxsc.