cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
658
Views
0
Helpful
2
Replies

IPS Modules in Active/Passive failover ASA config

graham.fleming
Level 1
Level 1

Hey guys,

We have two ASA's in an active/passive failover situation each with an AIP-SSM-20 IPS module.

Are these modules meant to synchronize their configs like the ASA's do? Or are they each a separate entity and each need to be configured separately?

Thanks for any help!

1 Accepted Solution

Accepted Solutions

marcabal
Cisco Employee
Cisco Employee

Each will need their own IP, and each will need to be separately configured.

They will not communicate with each other and will not share configuration.

You will need to ensure config changes in one are made on the other.

You monitoring station will need to pull events from both sensors.

The SSMs rely on the ASA for tracking TCP state so they will work fine within an ASA failover design.

View solution in original post

2 Replies 2

marcabal
Cisco Employee
Cisco Employee

Each will need their own IP, and each will need to be separately configured.

They will not communicate with each other and will not share configuration.

You will need to ensure config changes in one are made on the other.

You monitoring station will need to pull events from both sensors.

The SSMs rely on the ASA for tracking TCP state so they will work fine within an ASA failover design.

Thanks a lot for the information! By the way, is that made availalbe on Cisco's website anywhere? I looked through a lot of documentation and couldn't find it anywhere.

Review Cisco Networking products for a $25 gift card