AIP-SSM inline

Unanswered Question
Apr 20th, 2010

Hi,

i want the inline configuration for ASA and IPS.Iam sending my configuration, please see the attachment and tell me that the configuration in ASA and IPS module are correct or not.. if not, pelase tell me what are the changes to be done in the configuration.

1.Is Modular Policy Framework is required for inline configuration on ASA ?

2.In inline mode, how to block malicious traffic by using IDM? when to use inline interface pair,please explain it.

3.Is it manually do the IPS configuration as in primary,the same in secondary unit also?

How the signatures will get update in secondary unit?

4.Please tell me how to see the signatures in IDM and how to see the events (to be monitor) after i did the configuration in both the devices.

5.Is there any gui tools to view the logs,current traffic passing through ips,to view the events etc..

if there,please tell me how to configure & use that software, and where can i get it that software..

Please send the relavent document links for further details..

Give me some example signatures and how to see those events in IDM..

In ASA i've 2 interfaces,i want to put those in inline mode.. what's the configuration for 1 (inside) interface or for both interfaces..

please give clear details..

Thanks and regards,

kalyan.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Panos Kampanakis Wed, 04/21/2010 - 20:58

1. Yes

2. When you want toe IDS to be in between 2 vlans, bridge them and block malicious traffic and not have it cross from one vlan to the other yo use them.

4. If you launch IDM from the ASA's ASDM you have a GUI for all the IDS set up signatures etc.

5. ASDM

I hope it helps.

PK

akchakravarthi08 Thu, 04/22/2010 - 21:52

Hi mate,

Thanks for your reply. please see the configuration file in the attachment and tell me whether the configuration is correct or not..

where i can found IME software free download..normal cisco login is not sufficient to download the software from cisco site..

please give me your mobile number and e-mail address also..

please suggest me, who did the installation of AIP-SSM-10 inline mode recently..

if you know, please give me their mobile number or e-mail address to contact them to took online help..

please i need it..

Actions

This Discussion