18-21
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter18 Configuring the ASA 5500-X IPS SSP
New and Modified Commands
Two ASAs in Fail-Close Mode
If the ASAs are configured in fail-close mode, and if the ASA 5500-X IPSSSP on the active ASA
experiences a configuration change or a signature/signature engine update, traffic is stopped from
passing through the active ASA. No failover is triggered.
If the ASAs are configured in fail-close mode, and if the ASA 5500-X IPSSSP on the active ASA
experiences a SensorApp crash or a service pack upg rade, failover is triggered and traffic passes
through the ASA 5500-X IPS SSP that was previously the standby for the ASA5500-X IPS SSP.
Configuration Examples
Use the following configuration for the primary ASA:
interface GigabitEthernet0/7
description LAN Failover Interface
failover
failover lan unit primary
failover lan interface folink GigabitEthernet0/7
failover interface ip folink 172.27.48.1 255.255.255.0 standby 172.27.48.2
Use the following configuration for the secondary ASA:
interface GigabitEthernet0/7
description LAN Failover Interface
failover
failover lan unit secondary
failover lan interface folink GigabitEthernet0/7
failover interface ip folink 172.27.48.1 255.255.255.0 standby 172.27.48.2
New and Modified Commands
This section describes the new and modified Cisco ASA commands that suppor t the
ASA 5500-X IPS SSP and are used to configure the ASA 5500-X IPS SSP.
Note
All other Cisco ASA CLI commands are documented in the Cisco Security Appliance Command
Reference on Cisco.com at
http://www.cisco.com/en/US/products/ps6120/prod_command_reference_list.html.
This section contains the following topic:
allocate-ips, page 18-22