cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
622
Views
0
Helpful
7
Replies

ASA SSM IP address

perrymichael
Level 1
Level 1

Does the Ip address on the SSM have to be on a seperate subnet from the other interfaces, while running in promiscous mode?

7 Replies 7

jwalker
Level 3
Level 3

It can be on any of the subnets you want... We have many across the US and put them on a DMZ with a static IP to a public address..

a.kiprawih
Level 7
Level 7

Hi,

You can assign any IP, but recommended is IP Address belongs to your Management Vlan or secure subnet (you can even assign unused IP belongs to inside interface segment).

This is because SSM is your IPS module, and you need to allow only trusted/authorized users to access it.

However, pls note that the SSM's default gateway must be in the same subnet as the sensor's IP address or the sensor will generate an error and not accept the configuration change.

http://www.cisco.com/en/US/partner/products/hw/vpndevc/ps4077/products_configuration_guide_chapter09186a008045a77c.html#wp1031325

Pls rate all useful post(s).

Cheers!

AK

Ok so the SSM acts like a server on the network, although it is a module in the ASA

Bingo. The physical port on the AIP-SSM module is for management. The docs are very vaugue about this. THe sensing "port" is connected to the ASA via the blackplane.

HTH

Yes, it works almost the same like FWSM/IDSM modules in Cat6500, except for the physical management port.

Like mmorris11 said, everything works via backplane, except the mgt port.

Cheers!

Amrih

While setting up the sensor it requires a reboot, will this reboot the entire ASA or just the module itself.

Only the SSM, not the entire ASA.

Review Cisco Networking products for a $25 gift card