62-2
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter62 Configuring the ASA IPS Module
Information About the ASA IPS module
Traffic goes through the firewall checks before being forwarded to the ASA IPS module. When you
identify traffic for IPS inspection on the ASA, traffic flows through the ASA and the ASA IPS module
as follows. Note: This example is for “inline mode.” See the “Operating Modes” section on page62-2
for information about “promiscuous mode,” where the ASA only sends a copy of the traffic to the ASA
IPS module.
1. Traffic enters the ASA.
2. Incoming VPN traffic is decrypted.
3. Firewall policies are applied.
4. Traffic is sent to the ASA IPS module.
5. The ASA IPS module applies its security policy to the traffic, and takes appropriate actions.
6. Valid traffic is sent back to the ASA; the ASA IPS module might block some traffic according to its
security policy, and that traffic is not passed on.
7. Outgoing VPN traffic is encrypted.
8. Traffic exits the ASA.
Figure 62-1 shows the traffic flow when running the ASA IPS module in inline mode. In this example,
the ASA IPS module automatically blocks traffic that it identified as an attack. All other traffic is
forwarded through the ASA.
Figure62-1 ASA IPS module Traffic Flow in the ASA: Inline Mode
Operating Modes
You can send traffic to the ASA IPS module using one of the following modes:
Inline mode—This mode places the ASA IPS module directly in the traffic flow (see Figure62-1).
No traffic that you identified for IPS inspection can continue through the ASA without first passing
through, and being inspected by, the ASA IPS module. This mode is the most secure because every
packet that you identify for inspection is analyzed before being allowed through. Also, the ASA IPS
module can implement a blocking policy on a packet-by-packet basis. This mode, however, can
affect throughput.
Promiscuous mode—This mode sends a duplicate stream of traffic to the ASA IPS module. This
mode is less secure, but has little impact on traffic throughput. Unlike inline mode, in promiscuous
mode the ASA IPS module can only block traffic by instructing the ASA to shun the traffic or by
resetting a connection on the ASA. Also, while the ASA IPS module is analyzing the traffic, a small
ASA
Main System
IPS
Diverted Traffic
IPS inspection
VPN
Decryption
Firewall
Policy
Block
251157
inside outside