Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
AIP-SSM on a 5520 routing question

Using the management interface for ASDM, how should I setup the AIP? Currently my M0/0 is, the AIP is, the inside G0/2 is

The interfaces are all connected to a switch, with my management PC on Vlan 10, the M0/0 on Vlan 10, the switch has interface Vlan 10, and int vlan 4, the AIP and G0/2 are on Vlan 4. IP Routing is enabled on the switch. I cannot access the IPS management through ASDM this way. I Have tried it without IP Routing as well. What do I need to do in order to have full access to the IPS and ASA through the ASDM?

What is the preferred method to set this and the Trend Micro SSM-10? I have one of those also on the same setup, but with different addressing, the ASA for internet is, and the TM is, the M0/0 on that device is I would prefer to access both devices off the management Vlan using ASDM or the web interface for the modules as needed.


Re: AIP-SSM on a 5520 routing question

To get this working, do the following..

create static translations for both of your SSM modules from the inside to the management network for access to the ssms


static (


static (

allow access from the managment system to the ssms

access-list mgmt_in extended permit tcp any host eq 443

access-list mgmt_in extended permit tcp any host eq 22

access-list mgmt_in extended permit tcp any host eq 443

access-list mgmt_in extended permit tcp any host eq 22

access-group mgmt_in in interface management

allow managment access to the ASA from the mangement network

http enable

http management

ssh management

create ssh keys

crypto key zeroize rsa noconfirm

crypto key generate rsa usage-keys noconfirm

wr mem

** Please rate if this helps**

Re: AIP-SSM on a 5520 routing question

I had reconfigured it after I found the documentation for ASDM 6.0. In there I found out that the interface is for management, and traffic flows through the backplane. I put the AIP and TM on the same subnet as the management interface and was able to pull it all up in ASDM, only drawback is no internet access for either module, so I think I will need to setup some way of natting as you described, hopefully that will work.

Just to test this out, I did as you described, switched the AIP IP to the address and setup the static, and it didn't work, but I am just a tad confused, you show


Re: AIP-SSM on a 5520 routing question

Yes. The names in the static statement are the names you defined with the nameif command.

