18-22
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
Chapter18 Configuring the ASA 5500-X IPS SSP
allocate-ips
allocate-ips
To allocate an IPS virtual sensor to a security context if you have the ASA5500-X IPS SSP installed,
use the allocate-ips command in context configuration mode. To remove a virtual sensor from a context,
use the no form of this command.
allocate-ips sensor_name [mapped_name] [default]
no allocate-ips sensor_name [mapped_name] [default]
Syntax Description
Defaults No default behavior or values.
Command Modes The following table shows the modes in which you can enter the command:
default (Optional) Sets one sensor per context as the default sensor; if the context
configuration does not specify a sensor name, the context uses this default
sensor. You can only configure one default sensor per context. If you want to
change the default sensor, enter the no allocate-ips sensor_name command
to remove the current default sensor before you allocate a new default sensor.
If you do not specify a sensor as the default, and the context configuration
does not include a sensor name, then traffic uses the default sensor on the
ASA 5500-X IPS SSP.
mapped_name (Optional) Sets a mapped name as an alias for the sensor name that can be
used within the context instead of the actual sensor name. If you do not
specify a mapped name, the sensor name is used within the context. For
security purposes, you might not want the context administrator to know
which sensors are being used by the context. Or you might want to genericize
the context configuration. For example, if you want all contexts to use
sensors called “sensor1” and “sensor2,” then you can map the “highsec” and
“lowsec” senors to sensor1 and sensor2 in context A, but map the “medsec”
and “lowsec” sensors to sensor1 and sensor2 in context B.
sensor_name Sets the sensor name configured on the ASA 5500 -X IPS SSP. To view the
sensors that are configured on the ASA 5500-X IPS SSP, enter allocate-ips
?. All available sensors are listed. You can also enter the show ips command.
In the system execution space, the show ips command lists all available
sensors; if you enter it in the context, it shows the sensors you already
assigned to the context. If you specify a sensor name that does not yet exist
on the ASA 5500-X IPS SSP, you get an error, but the allocate-ips command
is entered as is. Until you create a sensor of that name on the
ASA 5500-X IPS SSP, the context assumes the sensor is down.
Command Mode
Firewall Mode Security Context
Routed Transparent Single
Multiple
Context System
Context configuration
••
——