01-15-2009 05:33 AM - edited 03-10-2019 04:27 AM
I have an AIP SSM 10 module on an ASA 5510. My management address of the ASA is still default at 192.168.1.1 and the management of the IPS is 192.168.1.2.
Internal addresses are 172.16.x.x, external addresses are 10.1.x.x
I would like to setup the SSM to monitor traffic coming inside from the outside interface. Haven't really seen any good documentation on this. Anyone help would be greatly appreciated.
01-17-2009 06:26 AM
Create a class-map to identify traffic:
access-list monitor-acl extended permit ip any 172.16.0.0 255.255.0.0 log
class-map IPS_TRAFFIC
match access-list monitor-acl
Create Policy-Map to define what should happen with the traffic:
policy-map IPS_POLICY
class IPS_TRAFFIC
ips inline fail-open
Bind Policy to Interface:
service-policy IPS_POLICY interface outside
01-22-2009 06:07 AM
Thanks, will try this today.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide