Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

ASA support for IPS in Transparent Multicontext mode

Hi,

Customer is asking for a solution wherein ASA will be in transparent mode. 2 of the interfaces will fall in Admin context while other two will be part of a new context, say Context Traffic1. Now as he is also buying AIP SSM module with the boxes he wants IPS functionality for traffic of both contexts.

The ASA are to be deployed in AA mode with each ASA catering to traffic of one Context.

I am really doubtful on the IPS module being available to both contexts as no interface is shared between these contexts and how will the traffic be available to IPS when the IPS interface can only be part of one context at one time. Plz respond ASAP.

1 REPLY
Community Member

Re: ASA support for IPS in Transparent Multicontext mode

ASA diverts packets to ASA-SSM just before the packet exits the egress interface (or before VPN encryption occurs, if configured) and after other firewall policies are applied. For example, packets that are blocked by an access list are not forwarded to ASA-SSM.Refer the following URL for more information

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids11/cliguide/clissm.htm#wp1033926

243
Views
0
Helpful
1
Replies
CreatePlease to create content