C-66
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
AppendixC Troubleshooting
Troubleshooting the ASA 5500-X IPS SSP
Two ASAs in Fail-Open Mode
If the ASAs are configured in fail-open mode and if the ASA5500-X IPS SSP on the active ASA
experiences a configuration change or a signature/signature engine update, traffic is still passed
through the active ASA without being inspected. Failover is not triggered.
If the ASAs are configured in fail-open mode, and if the ASA 5500-X IPS SSP on the active ASA
experiences a SensorApp crash or a service pack upg rade, failover is triggered and traffic passes
through the ASA 5500-X IPS SSP that was previously the standby ASA5500- XIPS SSP.
Two ASAs in Fail-Close Mode
If the ASAs are configured in fail-close mode, and if the ASA 5500-X IPSSSP on the active ASA
experiences a configuration change or a signature/signa ture engine update, traffic is stopped from
passing through the active ASA. No failover is triggered.
If the ASAs are configured in fail-close mode, and if the ASA 5500-X IPSSSP on the active ASA
experiences a SensorApp crash or a service pack upg rade, failover is triggered and traffic passes
through the ASA 5500-X IPS SSP that was previously the standby for the ASA5500-X IPS SSP.
Configuration Examples
Use the following configuration for the primary ASA:
interface GigabitEthernet0/7
description LAN Failover Interface
failover
failover lan unit primary
failover lan interface folink GigabitEthernet0/7
failover interface ip folink 172.27.48.1 255.255.255.0 standby 172.27.48.2
Use the following configuration for the secondary ASA:
interface GigabitEthernet0/7
description LAN Failover Interface
failover
failover lan unit secondary
failover lan interface folink GigabitEthernet0/7
failover interface ip folink 172.27.48.1 255.255.255.0 standby 172.27.48.2
The ASA 5500-X IPS SSP and the Normalizer Engine
The majority of the features in the Normalizer engine are not used on the ASA5500-X IPS SSP, because
the ASA itself handles the normalization. Packets on the ASA IPS modules go through a special path in
the Normalizer that only reassembles fragments and puts packets in the right order for the TCP stream.
The Normalizer does not do any of the normalization that is d one on an inline IPS appliance, because
that causes problems in the way the ASA handles the packets.
The following Normalizer engine signatures are not supported :
1300.0
1304.0
1305.0
1307.0
1308.0
1309.0