Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Gold

Multicontext ASA > single context AIP-SSM

Can I pass traffic from multiple firewall contexts in an ASA to a single context AIP-SSM module in-line mode?

Would that use multiple VLAN pairs to keep the traffic seperate?

2 REPLIES
Silver

Re: Multicontext ASA > single context AIP-SSM

I think it is possible to send AIP SSM traffic to ASA in inline mode. This mode places the AIP SSM directly in the traffic flow . No traffic that you identified for IPS inspection can continue through the adaptive security appliance without first passing through, and being inspected by, the AIP SSM. This mode is the most secure because every packet that you identify for inspection is analyzed before being allowed through. Also, the AIP SSM can implement a blocking policy on a packet-by-packet basis. This mode, however, can affect throughput.

Gold

Re: Multicontext ASA > single context AIP-SSM

Thank you for taking the time to answer, but I was asking about the use of MULTI-context ASA firewalls. They are multiple virtual firewalls that reside inside the same physical ASA. Can a single context IPS sensor module (AIP-SSM) perform promiscious or in-line inspection on packets to and from multiple virtual firewalls?

313
Views
0
Helpful
2
Replies
CreatePlease to create content