62-7
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter62 Configuring the ASA IPS Module
Configuring the ASA IPS module
(ASA 5510 and higher) Configure basic network settings for the IPS module. See the “(ASA 5510
and Higher) Configuring Basic Network Settings” section on page 62-10.
(ASA 5505) Configure the management VLAN and IP address for the IPS module. See the “(ASA
5505) Configuring Basic Network Settings” section on page62-11.
Step3 (ASA 5512-X through ASA 5555-X; may be required) Install the software module. See the “(ASA
5512-X through ASA 5555-X) Installing the Software Module” section on page62-12.
Step4 On the module, configure the inspection and protection policy, which determines how to inspect traffic
and what to do when an intrusion is detected. See the “Configuring the Security Policy on the ASA IPS
module” section on page62-13.
Step5 (ASA 5510 and higher, optional) On the ASA in multiple context mode, specify which IPS virtual
sensors are available for each context (if you configured virtual sensors). See the “Assigning Virtual
Sensors to a Security Context (ASA 5510 and Higher)” section on page62-15.
Step6 On the ASA, identify traffic to divert to the ASA IPS module. See the “Diverting Traffic to the ASA IPS
module” section on page62-16.
Connecting Management Interface Cables
Connect the management PC to the ASA management interface and the ASA IPS module management
interface.
Guidelines
Your cabling might differ depending on your network.
See the “Information About Management Access” section on page62-4.
Detailed Steps
ASA 5505
The ASA 5505 does not have a dedicated management interface. You must use an ASA VLAN to access
an internal management IP address over the backplane. For a factory default configuration, connect the
management PC to one of the following ports: Ethernet 0/1 through 0/7, which are assigned to VLAN 1.
Security
Services
Card Slot
1
2
POWER
48VDC
7
POWER over ETHERNET
6
543210
Console
RESET

Ports 1 − 7 VLAN 1

Default ASA IP: 192.168.1.1/IPS IP: 192.168.1.2

Default IPS Gateway: 192.168.1.1 (ASA)

ASA 5505

Management PC

(IP Address from DHCP)

Cisco ASA SSC-05 STATUS