Configuring the Aipssm on the Cisco ASA

Two Cisco ASAs protect the Chicago office internal network. The IP address configuration of both Cisco ASAs is illustrated in Figure 12-51.

Figure 12-51 Cisco ASAs at the Chicago Office

Figure 12-51 Cisco ASAs at the Chicago Office

The following are the IP addresses of each of the interfaces of the primary Cisco ASA (ASA-1):

• AIP-SSM Management interface: 10.200.30.3

The following are the IP addresses of each of the interfaces of the secondary Cisco ASA (ASA-2):

• AIP-SSM management interface: 10.200.30.4

The administrator configures the necessary access and address translation for internal services in a procedure that is similar to the steps you learned previously in this chapter. After performing these basic configuration steps, the security administrator initializes the AIP-SSM. To verify that the ASA-1 recognizes the AIP-SSM, the administrator uses the show module command, as shown in Example 12-6.

Example 12-6 Output of the show module Command

companyB-ASA1# show module Mod Card Type

Model

Serial No.

Mod

ASA 5520 Adaptive Security Appliance ASA5520-K8 ASA 5500 Series Security Services Module-10 ASA-SSM-10 MAC Address Range Hw Version Fw Version

Sw

JMX1113L0Y4 JAB101502D9 Version

Mod

001a.6d7c.8c95 to 001a.6d7c.8c99 2.0 0016.c79f.78c1 to 0016.c79f.78c1 1.0 SSM Application Name Status

1.0(11)2 8.0 1.0(10)0 6.0 SSM Application

(2) (2)E1 Version

Mod

IPS Up Status Data Plane Status

6.0(2)E1 Compatibility

0 1

Up Sys Not Applicable Up Up

The highlighted lines show that the module is running IPS Software Version 6.0(2)E1 and that it is operational.

The administrator logs into ASA-1 via the CLI and connects to the AIP-SSM using the session 1 command. This puts him on the AIP-SSM CLI. To initialize the AIP-SSM, the administrator uses the setup command, as demonstrated in Example 12-7.

Example 12-7 Initializing ASA-1AIP-SSM

sensor# setup

— System Configuration Dialog — At any point you may enter a question mark '?' for help. Use ctrl-c to abort configuration dialog at any prompt. Default settings are in square brackets '[]'. Current Configuration: service host network-settings host-ip 10.1.9.201/24,10.1.9.1 host-name sensor telnet-option disabled ftp-timeout 300 login-banner-text exit time-zone-settings offset 0

standard-time-zone-name UTC exit summertime-option disabled ntp-option disabled exit service web-server port 443

exit

Current time: Mon May 14 18:26:51 2007

Setup Configuration last modified: Mon May 14 17:45:30 2007 Continue with configuration dialog?[yes]: yes Enter host name[sensor]: companyB-AIP-SSM1

Enter IP interface[10.1.9.201/24,10.1.9.1]: 10.200.30.3/24,10.200.30.1

Enter telnet-server status[disabled]: Enter web-server port[443]: Modify current access list?[no]: yes Current access list entries:

No entries Permit: 10.200.30.0/24 Permit:

Modify system clock settings?[no]: no

Modify virtual sensor "vs0" configuration?[no]: yes

Current interface configuration

Command control: GigabitEthernet0/0 Unused:

GigabitEthernet0/1 Monitored: None

Add Monitored interfaces?[no]: yes Interface[]: GigabitEthernet0/1 Interface[]:

The following configuration was entered.

service host network-settings continues

Example 12-7 Initializing ASA-1AIP-SSM (Continued)

host-ip 10.200.30.3/24,10.200.30.1 host-name companyB-AIP-SSM1 telnet-option disabled access-list 10.200.30.0/24 ftp-timeout 300 no login-banner-text exit time-zone-settings offset 0

standard-time-zone-name UTC exit summertime-option disabled ntp-option disabled exit service web-server port 443

exit service analysis-engine virtual-sensor vs0

physical-interface GigabitEthernet0/1

exit exit

[0] Go to the command prompt without saving this config.

[1] Return back to the setup without saving this config.

[2] Save this configuration and exit setup. Enter your selection[2]: 2 Configuration Saved.

In Example 12-7, the administrator configures the AIP-SSM hostname, IP address, and subnet mask of the management interface, in addition to the default gateway. The administrator allows management access only from machines in the 10.200.30.0/24 management network. Also, the GigabitEthernet0/1 interface is enabled for traffic inspection. Finally, the administrator saves the configuration and exits the interactive setup session.

Continue reading here: Configuring Active Standby Failover on the Cisco ASA

Was this article helpful?

0 0