18-4
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter18 Configuring the ASA 5500-X IPS SSP
Creating Virtual Sensors for the ASA 5500-X IPS SSP
Creating Virtual Sensors for the ASA 5500-X IPS SSP
This section describes how to create virtual sensors on the ASA 5500-X IPS SSP, and contains the
following topics:
The ASA 5500-X IPS SSP and Virtualization, page18-4
Virtual Sensor Configuration Sequence for ASA 5500-X IPS SSP, page18-4
Creating Virtual Sensors, page 18-4
Assigning Virtual Sensors to Adaptive Security Appliance Contexts, page 18-7

The ASA 5500-X IPS SSP and Virtualization

The ASA 5500-X IPS SSP has one sensing interface, PortChannel 0/0. W hen you create multiple virtual
sensors, you must assign this interface to only one virtual sensor. For the other virtual sensors you do
not need to designate an interface.
After you create virtual sensors, you must map them to a security context on the adaptive security
appliance using the allocate-ips command. You can map many security contexts to many virtual sensors.
Note
The allocate-ips command does not apply to single mode. In this mode, the a daptive security appliance
accepts any virtual sensor named in a policy-map command.
The allocate-ips command adds a new entry to the security context database. A warning is issued if the
specified virtual sensor does not exist; however, the configuration is allowed. The configuration is
checked again when the service-policy command is processed. If the virtual sensor is not valid, the
fail-open policy is enforced.

Virtual Sensor Configuration Sequence for ASA 5500-X IPS SSP

Follow this sequence to create virtual sensors on the ASA5500-X IPS SSP, and to assign them to
adaptive security appliance contexts:
1.
Configure up to four virtual sensors.
2.
Assign the ASA 5500-X IPS SSP sensing interface (PortChannel 0/0) to one of the virtual sensors.
3.
(Optional) Assign virtual sensors to different contexts on the adaptive security appliance.
4.
Use MPF to direct traffic to the targeted virtual sensor.

Creating Virtual Sensors

Note
You can create four virtual sensors.