30-6
Cisco ASA Series Firewall ASDM Configuration Guide
Chapter30 Configuring the ASA CX Module
Licensing Requirements for the ASA CX Module
Do not configure ASA inspection on HTTP traffic.
Do not configure Cloud Web Security (ScanSafe) inspection. If you configure both the ASA CX
action and Cloud Web Security inspection for the same traffic, the ASA only performs the ASA CX
action.
Other application inspections on the ASA are compatible with the ASA CX module, including the
default inspections.
Do not enable the Mobile User Security (MUS) server; it is not compatible with the ASA CX
module.
Do not enable ASA clustering; it is not compatible with the ASA CX module.
If you enable failover, when the ASA fails over, any existing ASA CX flows are transferred to the
new ASA, but the traffic is allowed through the ASA without being acted upon by the ASA CX
module. Only new flows recieved by the new ASA are acted upon by the ASA CX module.
(9.1(1) and earlier) Does not support NAT 64. In 9.1(2) and later, NAT 64 is supported.
Licensing Requirements for the ASA CX Module
The ASA CX module and PRSM require additional licenses. See the ASA CX documentation for more
information.
Prerequisites
To use PRSM to configure the ASA, you need to install a certificate on the ASA for secure
communications. By default, the ASA generates a self-signed certificate. However, this certificate can
cause browser prompts asking you to verify the certificate because the publisher is unknown. To avoid
these browser prompts, you can instead install a certificate from a known certificate authority (CA). If
you request a certificate from a CA, be sure the certificate type is both a server authentication certificate
and a client authentication certificate. See the Chapter40, “Configuring Digital Cert ificates,” in the
general operations configuration guide for more information.
Guidelines and Limitations
Context Mode Guidelines
(9.1(2) and earlier) Supported in single context mode only. Does not support multiple context mode.
(9.1(3) and later) Supported in multiple context mode. See the following guidelines:
The ASA CX module itself (configured in PRSM) is a single context mode device; the
context-specific traffic coming from the ASA is checked against the common ASA CX policy.
For ASA CX module support, you cannot use the same IP addresses in multiple contexts; each
context must include unique networks.
Model License Requirement
All models Base License.