01-15-2009 05:33 AM - edited 03-10-2019 04:27 AM
I have an AIP SSM 10 module on an ASA 5510. My management address of the ASA is still default at 192.168.1.1 and the management of the IPS is 192.168.1.2.
Internal addresses are 172.16.x.x, external addresses are 10.1.x.x
I would like to setup the SSM to monitor traffic coming inside from the outside interface. Haven't really seen any good documentation on this. Anyone help would be greatly appreciated.
01-17-2009 06:26 AM
Create a class-map to identify traffic:
access-list monitor-acl extended permit ip any 172.16.0.0 255.255.0.0 log
class-map IPS_TRAFFIC
match access-list monitor-acl
Create Policy-Map to define what should happen with the traffic:
policy-map IPS_POLICY
class IPS_TRAFFIC
ips inline fail-open
Bind Policy to Interface:
service-policy IPS_POLICY interface outside
01-22-2009 06:07 AM
Thanks, will try this today.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: