IPS Modules in Active/Passive failover ASA config

Answered Question
Sep 23rd, 2009

Hey guys,

We have two ASA's in an active/passive failover situation each with an AIP-SSM-20 IPS module.

Are these modules meant to synchronize their configs like the ASA's do? Or are they each a separate entity and each need to be configured separately?

Thanks for any help!

I have this problem too.
0 votes
Correct Answer by marcabal about 7 years 4 months ago

Each will need their own IP, and each will need to be separately configured.

They will not communicate with each other and will not share configuration.

You will need to ensure config changes in one are made on the other.

You monitoring station will need to pull events from both sensors.

The SSMs rely on the ASA for tracking TCP state so they will work fine within an ASA failover design.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
marcabal Wed, 09/23/2009 - 08:01

Each will need their own IP, and each will need to be separately configured.

They will not communicate with each other and will not share configuration.

You will need to ensure config changes in one are made on the other.

You monitoring station will need to pull events from both sensors.

The SSMs rely on the ASA for tracking TCP state so they will work fine within an ASA failover design.

graham.fleming Wed, 09/23/2009 - 14:04

Thanks a lot for the information! By the way, is that made availalbe on Cisco's website anywhere? I looked through a lot of documentation and couldn't find it anywhere.

Actions

This Discussion