31-8
Cisco ASA Series Firewall ASDM Configuration Guide Chapter31 Configuring the ASA IPS Module Configuring the ASA IPS moduleConnecting the ASA IPS Management Interface
In addition to providing management access to the IPS module, the IPS management interface needs
access to an HTTP proxy server or a DNS server and the Internet so it can download global correlation,
signature updates, and license requests. This section describes recommended network configurations.
Your network may differ.
ASA 5510, ASA 5520, ASA 5540, ASA 5580, ASA 5585-X (HardwareModule), page 31-8ASA 5512-X through ASA 5555-X (Software Module), page 31-9ASA 5505, page 31-10

ASA 5510, ASA 5520, ASA 5540, ASA 5580, ASA 5585-X (Hardware Module)

The IPS module includes a separate management interface from the ASA.
If you have an inside router
If you have an inside router, you can route between the management network, which can include both
the ASA Management 0/0 and IPS Management 1/0 interfaces, and the ASA inside network. Be sure to
also add a route on the ASA to reach the Management network through the inside router.

ASA 5585-X

PWR
BOOT
ALARM
ACT
VPN
PS1
HDD1
PS0
HDD0
USB RESET
0
SFP1 SFP0 101234567 MGMT
0
1AUX CONSOLE
PWR
BOOT
ALARM
ACT
VPN
PS1
HDD1
PS0
HDD0
USB RESET
0
SFP1 SFP0 101234567 MGMT
0
1AUX CONSOLE

ASA Management 0/0

Default IP: 192.168.1.1

IPS Management 1/0

Default IP: 192.168.1.2

SSP

IPS SSP

334656
ASA Management 0/0InternetManagement PCProxy or DNS Server (for example)RouterASAIPS Management 1/0OutsideIPSManagementInsideIPS DefaultGatewayASA gateway for Management
334658