09-14-2006 07:16 PM - edited 03-10-2019 03:13 AM
With the ASA firewalls work as failover group,how can i config the IPS module of them work as failover too?When ASA firewall works,i just need config primary one,then,how to deal with IPS mudules of ASA firewall?
09-14-2006 07:42 PM
Hi .. I am assuming you are configuring Active/Standby right .? The Modules as such are almost independent of the ASA. And they are independent of each other. You would have to configure the modules manually with similar configuration. I think the only different set you might need to make unique is the sensor's management IP addresses. Everything else should be the same. In this way when Active ASA is up then traffic will be inspected by its sensor module. When failover takes over to the secondary ASA then traffic will flow by its interfaces and will be be inspected by its Sensor module. There will not be an automatic synchronization between the modules. Any changes will have to be done manually in every sensor.
I hope it helps .. please rate it if it does !!!
09-17-2006 05:07 PM
cool,thank you!
09-15-2006 12:45 AM
Hi,
There is NO failover capability of IPS modules in an ASA, which means the following:
1) You need to set them up as independent IPS modules, with different IP's.
2) If you make a change on one then you'll need to make the change on the other if you want them to be in sync.
3) If you update signatures on one then you'll also have to update signatures on the other to keep them in sync. (This is easier if you use CSM to create a signature policy - or you can configure all your IPS to get updates from an ftp server)
So, whenever the primary ASA is active you'll get events from the IP of the primary IPS, but in a failover scenario you'll suddenly start to get events from a different IP (the sensor in the secondary ASA).
One final tip - if you upgrade the software on the sensor in the primary ASA you'll cause a failover because a sensor reboot causes the ASA to think it's failed.
HTH
Andrew.
09-17-2006 05:03 PM
ok!that is great,thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide