Configuring the Aipssm on the Cisco ASA
Two Cisco ASAs protect the Chicago office internal network. The IP address configuration of both Cisco ASAs is illustrated in Figure 12-51.
Figure 12-51 Cisco ASAs at the Chicago Office
Figure 12-51 Cisco ASAs at the Chicago Office
The following are the IP addresses of each of the interfaces of the primary Cisco ASA (ASA-1):
• AIP-SSM Management interface: 10.200.30.3
The following are the IP addresses of each of the interfaces of the secondary Cisco ASA (ASA-2):
• AIP-SSM management interface: 10.200.30.4
The administrator configures the necessary access and address translation for internal services in a procedure that is similar to the steps you learned previously in this chapter. After performing these basic configuration steps, the security administrator initializes the AIP-SSM. To verify that the ASA-1 recognizes the AIP-SSM, the administrator uses the show module command, as shown in Example 12-6.
Example 12-6 Output of the show module Command
|
companyB-ASA1# show module Mod Card Type |
Model |
Serial No. |
||
|
Mod |
ASA 5520 Adaptive Security Appliance ASA5520-K8 ASA 5500 Series Security Services Module-10 ASA-SSM-10 MAC Address Range Hw Version Fw Version |
Sw |
JMX1113L0Y4 JAB101502D9 Version |
|
|
Mod |
001a.6d7c.8c95 to 001a.6d7c.8c99 2.0 0016.c79f.78c1 to 0016.c79f.78c1 1.0 SSM Application Name Status |
1.0(11)2 8.0 1.0(10)0 6.0 SSM Application |
(2) (2)E1 Version |
|
|
Mod |
IPS Up Status Data Plane Status |
6.0(2)E1 Compatibility |
||
|
0 1 |
Up Sys Not Applicable Up Up |
|||
The highlighted lines show that the module is running IPS Software Version 6.0(2)E1 and that it is operational.
The administrator logs into ASA-1 via the CLI and connects to the AIP-SSM using the session 1 command. This puts him on the AIP-SSM CLI. To initialize the AIP-SSM, the administrator uses the setup command, as demonstrated in Example 12-7.
Example 12-7 Initializing ASA-1AIP-SSM
sensor# setup
— System Configuration Dialog — At any point you may enter a question mark '?' for help. Use ctrl-c to abort configuration dialog at any prompt. Default settings are in square brackets '[]'. Current Configuration: service host network-settings host-ip 10.1.9.201/24,10.1.9.1 host-name sensor telnet-option disabled ftp-timeout 300 login-banner-text exit time-zone-settings offset 0
standard-time-zone-name UTC exit summertime-option disabled ntp-option disabled exit service web-server port 443
exit
Current time: Mon May 14 18:26:51 2007
Setup Configuration last modified: Mon May 14 17:45:30 2007 Continue with configuration dialog?[yes]: yes Enter host name[sensor]: companyB-AIP-SSM1
Enter IP interface[10.1.9.201/24,10.1.9.1]: 10.200.30.3/24,10.200.30.1
Enter telnet-server status[disabled]: Enter web-server port[443]: Modify current access list?[no]: yes Current access list entries:
No entries Permit: 10.200.30.0/24 Permit:
Modify system clock settings?[no]: no
Modify virtual sensor "vs0" configuration?[no]: yes
Current interface configuration
Command control: GigabitEthernet0/0 Unused:
GigabitEthernet0/1 Monitored: None
Add Monitored interfaces?[no]: yes Interface[]: GigabitEthernet0/1 Interface[]:
The following configuration was entered.
service host network-settings continues
Example 12-7 Initializing ASA-1AIP-SSM (Continued)
host-ip 10.200.30.3/24,10.200.30.1 host-name companyB-AIP-SSM1 telnet-option disabled access-list 10.200.30.0/24 ftp-timeout 300 no login-banner-text exit time-zone-settings offset 0
standard-time-zone-name UTC exit summertime-option disabled ntp-option disabled exit service web-server port 443
exit service analysis-engine virtual-sensor vs0
physical-interface GigabitEthernet0/1
exit exit
[0] Go to the command prompt without saving this config.
[1] Return back to the setup without saving this config.
[2] Save this configuration and exit setup. Enter your selection[2]: 2 Configuration Saved.
In Example 12-7, the administrator configures the AIP-SSM hostname, IP address, and subnet mask of the management interface, in addition to the default gateway. The administrator allows management access only from machines in the 10.200.30.0/24 management network. Also, the GigabitEthernet0/1 interface is enabled for traffic inspection. Finally, the administrator saves the configuration and exits the interactive setup session.
Continue reading here: Configuring Active Standby Failover on the Cisco ASA
Was this article helpful?