cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
520
Views
0
Helpful
2
Replies

New deployment with ASA & AIP-SSM module

DialerString_2
Level 3
Level 3

Hi guys and gals,

I'm thinking of deploying an ASA with IPS module AIP-SSM at my perimeter. I'm going to use Cisco IPS Manager Express (IME) to monitor the IPS to monitor the ASA. I have no plans on deploying an IDS device.


Question: Is IME designed to send notification about threats? What are some of the setups in your network? (Just poking with the last question.)

thx..

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

IME is designed just to monitor IPS (whether it is IPS appliance, AIP-SSM module on ASA, or other IPS module). IME is not capable on monitoring ASA.

IME can provide email notification on events which are being triggered on the IPS, while IPS itself can't. IME can also keep all the events triggered by the IPS, while IPS buffer is pretty small, therefore if you have huge events, the buffer gets overwritten pretty quickly.

Here is more information on IME if you are interested:

http://www.cisco.com/en/US/products/ps9610/index.html

View solution in original post

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

IME is designed just to monitor IPS (whether it is IPS appliance, AIP-SSM module on ASA, or other IPS module). IME is not capable on monitoring ASA.

IME can provide email notification on events which are being triggered on the IPS, while IPS itself can't. IME can also keep all the events triggered by the IPS, while IPS buffer is pretty small, therefore if you have huge events, the buffer gets overwritten pretty quickly.

Here is more information on IME if you are interested:

http://www.cisco.com/en/US/products/ps9610/index.html

You can always change the buffer size and there's probably a way to syslog those events. Halijen thanks for you reply and it was very helpful.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card