cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
698
Views
0
Helpful
4
Replies

AIP-SSM reload

Tshi M
Level 5
Level 5

does reloading the AIP-SSM module affect the ASA?

1 Accepted Solution

Accepted Solutions

Exactly. If you dont have a policy-map using SSM module, then you can reload the SSM module and it wont affect the traffic through ASA. To give you more information, here is a link which gives information on how to configure ASA to use SSM module:

http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/ssm.htm#wp1050744

Hope that helps.

Regards,

Vibhor.

View solution in original post

4 Replies 4

vitripat
Level 7
Level 7

There are few conditions here.

- If you have ASA pairs in failover and you reload the SSM module on Primary ASA, then Primary ASA will failover to secondary ASA.

- If you dont have failover and you are using SSM services:

a) If SSM is configured as "fail-open", things will keep working fine.

b) If SSM is configured as "fail-close", this will block the traffic through ASA till SSM module comes up.

- If ASA is not using SSM module services, there wont be no issues whatsoever.

Hope that helps.

Regards,

Vibhor.

Just to be clear, you are saying that if we aren't using the SSM module (i.e. the ASA is not configured to use it), we can safely reload it, right?

Exactly. If you dont have a policy-map using SSM module, then you can reload the SSM module and it wont affect the traffic through ASA. To give you more information, here is a link which gives information on how to configure ASA to use SSM module:

http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/ssm.htm#wp1050744

Hope that helps.

Regards,

Vibhor.

I haven't tried the reboot yet but once I do. I will rate it accordingly. Regards,

Review Cisco Networking products for a $25 gift card