cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
547
Views
19
Helpful
4
Replies

ASA5510 and IPS module

wilson_1234_2
Level 3
Level 3

We have an ASA 5510 with an IPS module.

Can the two be configured for access seperately?

For example someone having access to the ASDM can only view the firewall config but edit and manage the IPS module.

And the iopposite of view the IDS module and manage the firewall config.

The IPS module has its own IP Address.

4 Replies 4

Farrukh Haroon
VIP Alumni
VIP Alumni

Yes Wilson, just use separate passwords for each.

But just make sure both guys are good friends otherwise the IPS guy could block all traffic for the ASA guy and the ASA guy could shutdown/reset the IPS module using the CLI :)

Regards

Farrukh

We have our ASAs using AAA pointing to a TACACS server.

How would it be done in this case?

Hi Wilson,

you can add 2 user accounts to the AAA server, one is othorized to manage ASA and the other is othorized to manage IPS module. and you have to configure AAA authentication on the IPS module.

B.regards,

You can have separate usernames for IPS and ASA. To further secure this, you can use Network Access Restrictions (but they sometimes do not work well with security devices as they don't send the complete information). Also the IPS does not support AAA, so there you will have to use local database anyway (thereby isolating things).

Regards

Farrukh

Review Cisco Networking products for a $25 gift card