CHAPT ER
18-1
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
18
Configuring the ASA 5500-X IPS SSP
This chapter contains procedures that are specific to configuring the ASA 5500-X IPS SSP. It contains
the following sections:
Notes and Caveats for ASA 5500-X IPS SSP, page 18-1
Configuration Sequence for the ASA 5500-X IPS SSP, page 18-2
Verifying Initialization for the ASA 5500-X IPS SSP, page18-3
Creating Virtual Sensors for the ASA 5500-X IPS SSP, page18- 4
The ASA 5500-X IPS SSP and Bypass Mode, page 18-9
The ASA 5500-X IPS SSP and the Normalizer Engine, page 18-10
The ASA 5500-X IPS SSP and Memory Usage, page 18-11
The ASA 5500-X IPS SSP and Jumbo Packets, page 18-11
Reloading, Shutting Down, Resetting, and Recovering the ASA 5500-X IPS SSP, page 18-11
Health and Status Information, page18-12
ASA 5500-X IPS SSP Failover Scenarios, page18-20
New and Modified Commands, page 18-21

Notes and Caveats for ASA 5500-X IPS SSP

The following notes and caveats apply to configuring the ASA 5500-X IPS SSP:
The ASA 5500-X IPS SSP is supported in ASA 8.6.1 and later.
For the ASA 5500-X IPS SSP, normalization is performed by the adaptive security appliance and
not the IPS.
The ASA 5500-X IPS SSP does not support the inline TCP session tracking mode.
The ASA 5500-X IPS SSP does not support CDP mode.
Anomaly detection is disabled by default.
All IPS platforms allow ten concurrent CLI sessions.
The ASA 5500-X IPS SSP does not support bypass mode. The adaptive security appliance will
either fail open, fail close, or fail over depending on the configuration of the adaptive security
appliance and the type of activity being done on the IPS.