62-4
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter62 Configuring the ASA IPS Module
Information About the ASA IPS module
Figure62-4 Single Mode ASA with Multiple Virtual Sensors
Information About Management Access
You can manage the IPS application using the following methods:
Sessioning to the module from the ASA—If you have CLI access to the ASA, then you can session
to the module and access the module CLI. See the “Sessioning to the Module from the ASA (May
Be Required)” section on page62-9.
Connecting to the IPS management interface using ASDM or SSH—After you launch ASDM on the
ASA, ASDM connects to the module management interface to configure the IPS application. For
SSH, you can access the module CLI directly on the module management interface. (Telnet access
requires additional configuration in the module application). The module management interface can
also be used for sending syslog messages or allowing updates for the module application, such as
signature database updates. See the “Connecting Management Interface Cables” section on
page 62-7.
See the following information about the management interface:
ASA 5510, ASA 5520, ASA 5540, ASA 5580, ASA 5585-X—The IPS management interface
is a separate external Gigabit Ethernet interface. If you cannot use the default address (see the
“Default Settings” section on page 62-6), you can change the interface IP address and other
network parameters. See the “Configuring Basic IPS Module Network Settings” section on
page 62-9. The IPS management IP address can be on the same network as the ASA (connected
through a switch), or on a different network (through a router). If you use a different network,
be sure to set the IPS gateway as appropriate.
ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, ASA 5555-X—These models run the
ASA IPS module as a software module. The IPS management interface shares the
Management 0/0 interface with the ASA. Separate MAC addresses and IP addresses are
supported for the ASA and ASA IPS module. You must perform configuration of the IPS IP
address within the IPS operating system (using the CLI or ASDM). However, physical
characteristics (such as enabling the interface) are configured on the ASA. You can change the
interface IP address and other network parameters. You should set the default gateway to be an
upstream router instead of the ASA management interface. Because the ASA management
interface does not allow through-traffic, traffic destined to another network is not allowed
through the ASA. See the “Configuring Basic IPS Module Network Settings” section on
page 62-9.
Sensor
1
Sensor
2
Sensor
3
ASA
Main System
IPS
Traffic 1
Traffic 2
Traffic 3
251159