03-14-2006 10:26 PM - edited 02-21-2020 12:46 AM
Hi everybody,
Ive a few questions about ASA with AIP-SSM. Could you please clarify me?
1. Is the management interface of AIP-SSM necessary? Can I use IPS feature without it?
2. Can I use ASA as an IDS box? I mean just for sniffing traffic only. How can I connect it to network?
Please advice.
Thanks,
Nitass
03-15-2006 03:11 AM
1) AFAIK the mgmt interface is jus for that. Management only. IPS can very well work without that as the traffic to the IPS will be switched on the backplane.
2) The AIP-SSM can be used as an IDS. The ASA will have to pass traffic inline and redirect the traffic to the AIP-SSM in promiscuous mode.
03-15-2006 04:56 AM
Thanks for your reply.
Regarding to use AIP-SSM as IDS, I dont want to place it in the path of traffic. Id like to configure SPAN port or something like that on switch and connect it to the AIP-SSM. Can I do that? Whats interface that it should be used? Mgmt of AIP-SSM? ASAs Ethernet interfaces?
Please advice.
Thanks a lot,
Nitass
03-15-2006 05:06 AM
Doubt if you can use the AIP-SSM sitting in an ASA in such a scenario. The typical scenario is to put the ASA inline and push all the traffic to the SSM through the backplane using 'Span' (actually sending a copy through the backplane). The Mgmt interfaces are used for only mgmt.
This link will explain how to install AIP-SSM in promiscuous mode.
03-15-2006 07:56 AM
Really I just want to know if the ASA can replace the existing IDS device in the network. Because Ive gotten the notification email about the IPS device will be replaced with the ASA with AIP-SSM.
Any suggestion please let me know.
Thanks a lot,
Nitass
03-15-2006 03:40 PM
i guess they offer similar features if not identical. performance on ssm is better than the basic model of 42xx.
one matter is that 42xx has more than one interface, and thus it can sniff multiple network segment at the same time; whereas ssm has only one monitor interface.
03-15-2006 07:33 PM
Do you mean ASA with AIP-SSM can sniff traffic as IPS? I mean only one connection attach to the network.
Thanks a lot,
Nitass
03-16-2006 06:32 AM
If you are asking if the SSM can act as an IPS blocking attacks inline, the answer is yes. The AIP-SSM can act as either IPS or IDS
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide