Configuring the Initial Csc Ssm Settings

The CSC SSM must be configured independently of the ASA. You can use several methods to connect to and configure the CSC. Most often, you use ASDM as your interface to the CSC, although other methods are discussed as they are needed. You should use the following steps to configure a CSC SSM:

1. Verify the CSC SSM status.

After a CSC SSM is installed in an ASA chassis, you should verify that the module is powered up and available. You can do that with the show module ASA command, as shown in the following example. Here, the CSC SSM is listed as ASA module 1 in the "up" state.

Code View: Scroll / Show All

Firewall# show module

Mod Card Type Model Serial

0 ASA 5510 Adaptive Security Appliance ASA5510 JMX1014K070

1 ASA 5500 Series Content Security Services Mo ASA-SSM-CSC-10 JAF10252436

Mod MAC Address Range Hw Version Fw Version Sw Version

0 0016.c789.c8a4 to 0016.c789.c8a8 1.1

1 0018.7317.8eb3 to 0018.7317.8eb3 1.0 6.1

(Build#1519)

Mod SSM Application Name Version

Status

SSM Application

1 CSC SSM Mod Status

Data Plane Status

0 Up Sys

1 Up Firewall#

Not Applicable Up

6.1 (Build#1519) Compatibility

2. Start the CSC Setup Wizard.

The CSC SSM must be configured with some initial information, such as an IP address, basic network settings, and license keys, before it can begin to operate. You should attempt to configure these settings through ASDM first, before trying any other methods.

Within ASDM, click on the Configuration tab at the top of the screen. Then click on the Trend Micro Content Security button on the left side of the screen. If the CSC SSM has never been configured before, you should see the CSC Setup Wizard window appear, as shown in Figure 12-4.

Figure 12-4. The CSC Setup Wizard Begins the Initial Configuration

If you see a window titled Connecting to CSC..., as shown in Figure 12-5, instead of the CSC Setup Wizard, the CSC SSM has probably been previously configured. The ASDM fetches the last known management interface IP address from the CSC and offers to use it. If you do not recognize the management IP address, you need to reconfigure the IP address information. Refer to the section ""Repairing the Initial CSC Configuration" in this chapter for more information.

Figure l2-5. A CSC with Preexisting IP Information

M Connecting to CSC...

ASDM will make a new connection to the CSC software running on the 55M module in this ASA system. ASDM connects to this using a separate connection to the IP address of the management port on the SSM module. In the below fields, specify the IP Address to be used to connect to the CSC subsystem. You will then be prompted for a CSC management password,

© Management IPJddress: 192.163.11^ O Other IP Address or Hostname:

Port:

Continue

Cancel

Help

Otherwise, the Connecting to CSC... window selects the default IP address that has been configured for the CSC's management interface. This is fine if your ASDM client can reach the management interface using that address. Suppose the management interface is located on a DMZ interface, but is translated to a different address on the outside of the ASA. In this case, you should select the Other IP Address or Hostname button and enter the translated IP address.

After you are connected to the CSC, you can click on the Wizard Setup link to the left of the window and then on the Launch Setup Wizard button to launch the CSC Setup Wizard.

3. Enter the CSC activation codes.

A CSC SSM can have the following two license activation codes:

• Base license— Enables the Anti-Virus, Anti-Spyware, and File Blocking features

• Plus license— Enables the Anti-Spam, Anti-Phishing, Content Filtering, and URL Blocking/Filtering features

If your CSC module does not already have valid activation codes entered, you should enter them in the fields shown in Figure 12-4. You can obtain the activation codes by browsing to http://www.cisco.com/go/license and entering the Product Activation Key (PAK) information that was included with the CSC module.

After the activation codes have been entered into the CSC Setup Wizard, click the Next> button.

4. Enter the IP Configuration.

The CSC Setup Wizard should open an IP Configuration window, as shown in Figure 12-6. Enter the CSC management interface IP address, subnet mask, and default gateway. You should also enter the IP addresses of a primary DNS and an optional secondary DNS. If your environment requires outbound connections to pass through a proxy server, you can also enter the IP address and port number of the proxy server.

Figure 12-6. Entering the CSC Management IP Configuration

[View full size image]

5. Enter the CSC Host configuration.

In the window shown in Figure 12-7, you can enter a hostname and domain name that identifies the CSC SSM management interface. The CSC must also know about the e-mail domain used in your network so that it can examine incoming e-mail.

Figure 12-7. Entering the CSC Host Configuration

[View full size image]

If you want the CSC SSM to send e-mail notifications as it operates, you should enter the email address where those notifications should be sent. The notifications are sent using SMTP, so you should also enter the IP address of your local SMTP server, along with the TCP port used. By default, SMTP uses TCP port 25.

After you have entered the IP configuration information, click the Next> button.

6. Configure management access to the CSC.

You can limit access to the CSC management interface if your security policies require it. In the window shown in Figure 12-8, you can enter an IP address and a subnet mask that identify hosts that are permitted to access the CSC management interface. This can be a single host or an entire subnet. After you enter the address information, you can click the Add>> button to add it to the list of selected entries. By default, a host at any IP address is allowed to reach the CSC, as shown by the 0.0.0.0/0 entry in the list.

Figure 12-8. Limiting Access to the CSC Management Interface

Click the Next> button to continue.

7. Configure the CSC management passwords.

After the initial configuration is completed, you are challenged to enter a password for all future connections to the CSC management interface. By default, the CSC uses password cisco. Because this is commonly known, you should change it now in the window shown in Figure 12-9. However, if you want to leave the password as it is, you can leave the password entries untouched and they will not be changed.

Figure 12-9. Configuring the CSC Management Password

[View full size image]

Click the Next> button to continue.

8. Identify traffic to be inspected.

By default, the CSC inspects HTTP, SMTP, POP3, and FTP traffic between any two hosts. You can configure more specific traffic in the window shown in Figure 12-10. Click the Add button to bring up the Specify Traffic for CSC Scan window, where you can enter source and destination addresses, as well as specific protocol and port numbers.

Figure 12-10. Tuning the CSC Traffic Inspection

[View full size image]

9. Complete the initial configuration.

You should see a window showing a summary of each of the initial CSC configuration settings, as shown in Figure 12-11. At this point, ASDM automatically pushes the settings to the CSC, using an out-of-band connection.

Figure 12-11. ASDM Updates the CSC with the Initial Configuration

[View full size image]

□ CSC Setup Wizard

CSC Setup Whrard

Mftattti Codas

IP Piramfttri

ThahoA has¡fedifcafi 192, ¡66,1 IB, 10 255,255,255,0 Dira th« ptflway ti i?i,i6s.no,i. Th« cnRavOtg wrva-& at ja,]63,97.5 jnd tr»Mwttoy urvw is * 1Î6.163.3.10. rib pOïï«tvtr ¡4 confijntd.

hteit a iJ t'ouiif i NM IK-I

Hwhost nains ntui md (ha domain nama «

Ihe ,J«nan nart for nioinng t irai it myH.MfkVi/.tim. Th.: t nii AdrtMUatb't e-nai fldicH n hoc jby®ii.ro*J. The r-mJ wrv(r is at 13.163.1B btcnn» en pgit 35.

MjrflfltiWit ¡Kirri'. List

psiurtcfd

The iMitKjti hfiî nsCbeoi (hjngei.

Help

At this point, the CSC management interface has been activated for use. From now on, you are prompted for a password when you try to monitor or configure the CSC.

Continue reading here: Connecting to the CSC Management Interface

Was this article helpful?

0 0