Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Hi Can anyone explain how IPS works in ASA firewalls and SSL/IPSEC VPN configurations?

Hi..

       Hi Can anyone explain how IPS works in ASA firewalls and SSL/IPSEC VPN configurations?

1 REPLY
VIP Purple

Hi Can anyone explain how IPS works in ASA firewalls and SSL/IPS

You have to distinguish three scenarios:

1) IPSec/SSL through the ASA with the IPS-module

The IPS can not look into the encrypted traffic, but can analyse the cleartext-headers for attacks. To inspect the payload you need an IPS-apliance that sits behind the VPN-termination-point.

2) IPSec and SSL-VPNs (tunneled) that are terminated on the ASA

This traffic can be inspected by the IPS-module in the ASA.

3) clientless SSL terminated on the ASA

This traffic is not inspected by the IPS-module in the ASA.

-- 
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni

559
Views
0
Helpful
1
Replies
CreatePlease to create content