cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1040
Views
0
Helpful
5
Replies

AIP-SSM in cluster

Hello,

we have a fail-over ASA cluster, with 2 AIP-SSM IPS, each one in one ASA. There is a way to config IPS module in cluster mode like ASA, or have a configuration mirroring between them ?

Thank you really much.
Best regards Antonello.

1 Accepted Solution

Accepted Solutions

Scott Fringer
Cisco Employee
Cisco Employee

Antonello;

  Configuration mirroring between AIP-SSMs is not currently available.  You can mimic this process by copying the current-configuration from the active AIP-SSM to a FTP server, edit the configuration to remove the host specific details (IP address, etc) and then copy that configuration to the stand-by AIP-SSM.

  Another option would be to invest in Cisco Security Manager (CSM) and create a shared policy that is applied to both AIP-SSM.

Scott

View solution in original post

5 Replies 5

Scott Fringer
Cisco Employee
Cisco Employee

Antonello;

  Configuration mirroring between AIP-SSMs is not currently available.  You can mimic this process by copying the current-configuration from the active AIP-SSM to a FTP server, edit the configuration to remove the host specific details (IP address, etc) and then copy that configuration to the stand-by AIP-SSM.

  Another option would be to invest in Cisco Security Manager (CSM) and create a shared policy that is applied to both AIP-SSM.

Scott

Scott, you are my best friend :).

We already have a CSM, for me is new product so I didn´t think to use it in this issue. I think we are going to explore this possibility.

Thank you again!

Antonello;

  It is certainly a pleasure to be able to provide guidance on ways to accomplish your needs. Don't hesitate to come back with any other questions you may have, and we in the community will work to assist you.

  CSM an be a bit tricky to get started with, but once you understand its potential, it can make configuration (policy) management of multiple/various Cisco security devices much easier to maintain.

Scott

Scott, I need your help again.

Look, I tried to follow your tip about adding IPS in CSM, but I found this problem:

Our CSM is integrated with ACS, but IPS 6.1 doesn´t support AAA. When I try to add it, CSM tell me I need to add it before in ACS. I tried to add a dummy entry in ACS, but it doesn´t work.

I found this post, I haven´t tried yet, because I would like to find a less trick solution.
https://supportforums.cisco.com/message/959153

Do you know a procedure or a link in documentation where I can find the solution, I was searching for almost all day yesterday but I couldn´t find anything.

Thank you again.
Best regards Antonello.

Scott, never mind I resolve it.

I forgot the first lemma in information technology: be patient.

I forgot CWS can take long time  before to it can see a allowed device from ACS. To accelerate the process I just restart CMS daemon manager.

If you need here are the steeps:

1. Add a dummy entry of IPS in ACS. For dummy entry I mean just add IPS without any config in the device.

2. (Optional) Add the device in CSM ciscoworks backend.

3. Restart CSM daemon manager.

4. (Optional) If you previous add IPS in CSM ciscoworks backend, remove it

5. Add IPS through CSM client.

6. enjoy.

Thank you anyway to read :).

Cheers Antonello.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card