5-20
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter 5 Managing Policies
Discovering Policies
Discover Policies for
Security Contexts
(Not available for bulk
rediscovery)
Whether to discover policies for each security context that is configured
on a firewall device running in multiple-context mode. This field
applies only to PIX, ASA, and FWSM devices.
When deselected, Security Manager treats the entire device as having a
single set of policies configured in single-context mode.
For more information about security contexts, see Chapter 57,
“Configuring Security Contexts on Firewall Devices”.
Policies to Discover (for
single-device discovery)
Discover Device Settings (for
bulk rediscovery )
The policy types to discover on the selected device.
Note For bulk rediscovery, from the Discover drop-down menu,
choose Policies and Inventory to enable the following options,
Inventory Only to discover the inventory without discovering
other policy types, or Detect ASA-CX Module to determine if
a CX module is installed without discovering other policies. If
the drop-down list has Multiple Values selected, this means
that the devices in the selected group have different discovery
options selected. If you change the selection, your change
applies to all the devices in the group.
The discovery options are:
Detect ASA-CX Module—Determines if a CX module is installed;
see Detecting ASA CX Modules, page69-10 for more information.
Available only with certain ASA 4.1+ devices; not displayed here
in the Bulk Rediscovery dialog box.
Inventory—Includes device information such as the hostname and
domain name, interfaces, and security contexts (for firewall
devices running in multiple-context mode). On Cisco IOS routers,
this option also discovers all interface-related policies, such as
DSL, PPP, and PVC policies.
Platform Settings—Includes all platform-specific policies that can
be configured on the selected device.
Firewall Services—Includes all firewall service policies. For more
information, see Chapter 12, “Introduction to Firewall Services”.
RA VPN Policies—Includes all IPSec and SSL remote access VPN
policies that are configured on the selected device. This option is
disabled if the device does not support remote access VPN
configuration. For more information, see Chapter 29, “Managing
Remote Access VPNs: The Basics”.
IPS Policies—Includes all IPS policies that are configured on the
selected device. For more information, see Overview of IPS
Configuration, page 35-5 or Overview of Cisco IOS IPS
Configuration, page 44-3.
Table5-2 Create Discovery Task Dialog Box (Continued)
Element Description