Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Turn off firewall for ASA running IPS

I have two ASA devices. 5510 with IPS and 5520 with Content scanning. The 5510 sits behind the 5520. I want the 5520 to perform all firewall functions along with content scanning for spyware and viruses. The 5510 will be used purely for IPS for traffic that has been allowed through the 5520. Is there a way to effectively turn off the firewall on the 5510? Is there any inherent problems with this configuration?

Regards,

James Krysinski

2 REPLIES
Silver

Re: Turn off firewall for ASA running IPS

Yes, you can turn off the firewall on ASA. For this remove any interface which is in outside or inside; better place all interfaces in same security level. Now permit all traffic between the same security level interfaces and remove any other config which was used for firewall.

New Member

Re: Turn off firewall for ASA running IPS

Thanks for the tip. I followed your advice and was able to have the 5510 perform just IPS.

Thanks again.

122
Views
0
Helpful
2
Replies