Using many sensor on AIP-SSM 20

Unanswered Question
May 18th, 2010
User Badges:

I have an ASA 5540 with AIP-SSM20. I use Gi0/0 for DMZ1 and Gi0/1 for DMZ2, then I create two virtual sensor: vs0 and Vs1. Could I use policy-map to force vs0 to protect servers in DMZ1 and vs1 to protect servers in DMZ2?


Thank every one alot ! 

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Diego Armando C... Tue, 05/18/2010 - 10:20
User Badges:
  • Bronze, 100 points or more

Hello,


Yes you can do that. Just create 2 ACL to match the traffic that you want to monitor.


Here is the link to configure the AIP-SSM


http://www.cisco.com/en/US/docs/security/ips/5.1/configuration/guide/cli/cliSSM.html#wp1033926


Check this out

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807335ca.shtml#c4



ciscoasa#configure terminal
ciscoasa(config)#access-list traffic_for_ips deny ip 10.2.2.0 255.255.255.0 192.168.1.0 255.255.255.0 
ciscoasa(config)#access-list traffic_for_ips permit ip any 192.168.1.0 255.255.255.0 
ciscoasa(config)#access-list traffic_for_ips deny ip 192.168.1.0 255.255.255.0 10.2.2.0 255.255.255.0 
ciscoasa(config)#access-list traffic_for_ips permit ip 192.168.1.0 255.255.255.0 any 
ciscoasa(config)#class-map ips_class_map 
ciscoasa(config-cmap)#match access-list traffic_for_ips
ciscoasa(config)#policy-map interface_policy
ciscoasa(config-pmap)#class ips_class_map
ciscoasa(config-pmap-c)#ips inline fail-open 
ciscoasa(config)#service-policy interface_policy interface dmz

Apply the Service policy in the DMZ1 and in the DMZ2
Of course the ACL are doing to be different.
I think that in the command 
ciscoasa(config-pmap-c)#ips inline fail-open
you can specify the VS0 or VS1
check this with the interrogation key (?)
Hope it helps.
nguyenthinh Tue, 05/18/2010 - 19:22
User Badges:

Thank for your kindly reply!


I still have an unclear thing. I create two virtual sensors but ASA and AIP-SSM just have one backplane interface Gi0/1; how can I map one interface to two virtual sensors?

Actions

This Discussion

Related Content