06-23-2014 06:20 PM - edited 03-10-2019 06:12 AM
Hi Everyone,
Need some help from expert who familiar with ASA-IPS.
Currently i have implemented ASA-IPS. I have set that the IPS address as my management ip range. But somehow, i found that my management ip range are not permitted to internet.
Is that possible I change my IPS's ip address to other ip range which can access internet and during the ip address change, will the IPS will trigger downtime?
Solved! Go to Solution.
07-04-2014 12:27 PM
Tppsupport,
What ASA model do you have? is that IPS software based? Check out who's default gateway of IPS and if is it firewall check out about NAT. " will the IPS will trigger downtime?" No. In failover scenario will trigger failover in case IPS becomes "unresponsive" or down from backplane's perspective. So configuration changes will not trigger failover just if reload is necessary.
Johan.
07-04-2014 12:27 PM
Tppsupport,
What ASA model do you have? is that IPS software based? Check out who's default gateway of IPS and if is it firewall check out about NAT. " will the IPS will trigger downtime?" No. In failover scenario will trigger failover in case IPS becomes "unresponsive" or down from backplane's perspective. So configuration changes will not trigger failover just if reload is necessary.
Johan.
07-06-2014 04:27 PM
Hi Johflore,
Yes, I found was the routing and gateway issue. After put the correct route and gateway. it able to connect to internet and update the IPS signature.
Thanks
Tommy
07-07-2014 09:10 AM
Tommy,
Thanks for reply and great news to know issue is resolved.
It was a pleasure.
Johan.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide