31-27
Cisco ASA Series Firewall CLI Configuration Guide
Chapter31 Configuring the ASA IPS Module
Feature History for the ASA IPS module
ciscoasa(config)# class-map my-ips-class
ciscoasa(config-cmap)# match access-list my-ips-acl
ciscoasa(config)# class-map my-ips-class2
ciscoasa(config-cmap)# match access-list my-ips-acl2
ciscoasa(config-cmap)# policy-map my-ips-policy
ciscoasa(config-pmap)# class my-ips-class
ciscoasa(config-pmap-c)# ips inline fail-open sensor sensor1
ciscoasa(config-pmap)# class my-ips-class2
ciscoasa(config-pmap-c)# ips inline fail-open sensor sensor2
ciscoasa(config-pmap-c)# service-policy my-ips-policy interface outside
Feature History for the ASA IPS module
Table31-2 lists each feature change and the platform release in which it was implemented.
Table31-2 Feature History for the ASA IPS module
Feature Name
Platform
Releases Feature Information
AIP SSM 7.0(1) We introduced support for the AIP SSM for the ASA 5510,
5520, and 5540.
The following command was introduced: ips.
Virtual sensors (ASA 5510 and higher) 8.0(2) Virtual sensor support was introduced. Virtual sensors let
you configure multiple security policies on the ASA IPS
module.
The following command was introduced: allocate-ips.
AIP SSC for the ASA 5505 8.2(1) We introduced support for the AIP SSC for the ASA 5505.
The following commands were introduced:
allow-ssc-mgmt, hw-module module ip, and hw-module
module allow-ip.
Support for the ASA IPS SSP-10, -20, -40, and -60 for
the ASA 5585-X
8.2(5)/
8.4(2)
We introduced support for the ASA IPS SSP-10, -20, -40,
and -60 for the ASA 5585-X. You can only install the ASA
IPS SSP with a matching-level SSP; for example, SSP-10
and ASA IPS SSP-10.
Note The ASA 5585-X is not supported in Version 8.3.