Managing Aip Ssm and Csc Ssm

The Cisco ASA 5500 series adaptive security appliance supports a variety of SSMs. This chapter describes how to configure the adaptive security appliance to support an AIP SSM or a CSC SSM, including how to send traffic to these SSMs.

For information about the 4GE SSM for the ASA 5000 series adaptive security appliance, see Chapter 5, "Configuring Ethernet Settings and Subinterfaces".

Note The Cisco PIX 500 series security appliances cannot support SSMs.

This chapter includes the following sections:

• Managing the AIP SSM, page 22-1

• Managing the CSC SSM, page 22-5

• Checking SSM Status, page 22-13

• Transferring an Image onto an SSM, page 22-14

This section contains the following topics:

• Getting Started with the AIP SSM, page 22-2

• Diverting Traffic to the AIP SSM, page 22-2

Sessioning to the AIP SSM and Running Setup, page 22-4

The ASA 5500 series adaptive security appliance supports the AIP SSM, which runs advanced IPS software that provides further security inspection. The adaptive security appliance diverts packets to the AIP SSM just before the packet exits the egress interface (or before VPN encryption occurs, if configured) and after other firewall policies are applied. For example, packets that are blocked by an access list are not forwarded to the AIP SSM.

Continue reading here: Sessioning to the Aip Ssm and Running Setup

Was this article helpful?

0 0