Sessioning to the Aip Ssm and Running Setup
After you have completed configuration of the ASA 5500 series adaptive security appliance to divert traffic to the AIP SSM, session to the AIP SSM and run the setup utility for initial configuration. % _
Note You can either session to the SSM from the adaptive security appliance (by using the session 1
command) or you can connect directly to the SSM using SSH or Telnet on its management interface. Alternatively, you can use ASDM.
To session to the AIP SSM from the adaptive security appliance, perform the following steps:
Step 1 Enter the session 1 command to session from the ASA 5500 series adaptive security appliance to the AIP SSM:
hostname# session 1
Opening command session with slot 1.
Connected to slot 1. Escape character sequence is 'CTRL-^X1.
Step 2 Enter the username and password. The default username and password are both cisco.
Note The first time you log in to the AIP SSM you are prompted to change the default password. Passwords must be at least eight characters long and not a dictionary word.
login: cisco Password:
Last login: Fri Sep 2 06:21:20 from xxx.xxx.xxx.xxx
This product contains cryptographic features and is subject to United States and local country laws governing import, export, transfer and use. Delivery of Cisco cryptographic products does not imply third-party authority to import, export, distribute or use encryption. Importers, exporters, distributors and users are responsible for compliance with U.S. and local country laws. By using this product you agree to comply with applicable laws and regulations. If you are unable to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at: http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to [email protected].
There is no license key installed on the system. Please go to http://www.cisco.com/go/license to obtain a new license or install a license. AIP SSM#
|
Note |
If you see the preceding license notice (which displays only in some versions of software), you can |
|
ignore the message until you need to upgrade the signature files on the AIP SSM. The AIP SSM |
|
|
continues to operate at the current signature level until a valid license key is installed. You can install |
|
|
the license key at a later time. The license key does not affect the current functionality of the AIP SSM. |
|
|
Step 3 |
Enter the setup command to run the setup utility for initial configuration of the AIP SSM: |
|
AIP SSM# setup |
|
|
You are now ready to configure the AIP SSM for intrusion prevention. See the following two guides for |
|
|
AIP SSM configuration information: |
|
|
• Configuring the Cisco Intrusion Prevention System Sensor Using the Command Line Interface |
|
|
• Cisco Intrusion Prevention System Command Reference |
|
|
Managing |
the CSC SSM |
|
This section contains the following topics: |
|
|
• About the CSC SSM, page 22-5 |
|
|
• Getting Started with the CSC SSM, page 22-7 |
|
|
• Determining What Traffic to Scan, page 22-9 |
|
|
• Limiting Connections Through the CSC SSM, page 22-11 |
|
|
• Diverting Traffic to the CSC SSM, page 22-11 |
|
|
About the CSC SSM |
|
|
The ASA 5500 series adaptive security appliance supports the CSC SSM, which runs Content Security |
|
|
and Control software. The CSC SSM provides protection against viruses, spyware, spam, and other |
|
|
unwanted traffic. It accomplishes this by scanning the FTP, HTTP, POP3, and SMTP traffic that you |
|
|
configure the adaptive security appliance to send to it. |
|
|
Figure 22-1 illustrates the flow of traffic through an adaptive security appliance that has the following: |
|
|
• A CSC SSM installed and setup. |
|
|
• A service policy that determines what traffic is diverted to the SSM for scans. |
|
|
In this example, the client could be a network user who is accessing a website, downloading files from |
|
|
an FTP server, or retrieving mail from a POP3 server. SMTP scans differ in that you should configure |
|
|
the adaptive security appliance to scan traffic sent from outside to SMTP servers protected by the |
|
|
adaptive security appliance. |
|
|
X |
|
|
Note |
The CSC SSM can scan FTP file transfers only when FTP inspection is enabled on the adaptive security |
|
appliance. By default, FTP inspection is enabled. |
|
Figure 22-1 Flow of Scanned Traffic with CSC SSM
Security Appliance
Request sent
inside
Reply forwarded
Client
Main System modular service policy
Diverted Traffic
Diverted Traffic
CSC SSM
CSC SSM
Request forwarded outside
Reply sent
Server
Note
You use ASDM for system setup and monitoring of the CSC SSM. For advanced configuration of content security policies in the CSC SSM software, you access the web-based GUI for the CSC SSM by clicking links within ASDM. Use of the CSC SSM GUI is explained in the Trend Micro InterScan for Cisco CSC SSM Administrator Guide.
ASDM and the CSC SSM maintain separate passwords. You can configure their passwords to be identical; however, changing one of these two passwords does not affect the other password.
The connection between the host running ASDM and the adaptive security appliance is made through a management port on the adaptive security appliance. The connection to the CSC SSM GUI is made through the SSM management port. Because these two connections are required to manage the CSC SSM, any host running ASDM must be able to reach the IP address of both the adaptive security appliance management port and the SSM management port.
Figure 22-2 shows an adaptive security appliance with a CSC SSM that is connected to a dedicated management network. While use of a dedicated management network is not required, we recommend it. Of particular interest in Figure 22-2 are the following:
• An HTTP proxy server is connected to the inside network and to the management network. This enables the CSC SSM to contact the Trend Micro update server.
• The management port of the adaptive security appliance is connected to the management network. To permit management of the adaptive security appliance and the CSC SSM, hosts running ASDM must be connected to the management network.
• The management network includes an SMTP server for email notifications for the CSC SSM and a syslog server that the CSC SSM can send syslog messages to.
Figure 22-2 CSC SSM Deployment with a Management Network inside
Trend Micro Update Server
192.168.100.1
HTTP Proxy management port
Main System outside
10.6.13.67
Trend Micro Update Server
Main System outside
10.6.13.67
ASDM
192.168.50.1
ASDM
CSC SSM
management port
Syslog
Notifications SMTP Server
Notifications SMTP Server
Step 1
Step 2
Step 3
CSC SSM cannot suport stateful failover, because the CSC SSM does not maintain connection information and therefore cannot provide the failover unit with information necessary for stateful failover. The connections that a CSC SSM is scanning are dropped upon failure of the security appliance that the CSC SSM is installed in. When the standby adaptive security appliance becomes active, it will forward the scanned traffic to its CSC SSM and the connections will be reset.
Before you receive the security benefits provided by a CSC SSM, you must perform several steps beyond simple hardware installation of the SSM. This procedure provides an overview of those steps.
To configure the adaptive security appliance and the CSC SSM, follow these steps:
If the CSC SSM did not come pre-installed in a Cisco ASA 55GG series adaptive security appliance, install it and connect a network cable to the management port of the SSM. For assistance with installation and connecting the SSM, see the Cisco ASA 5500 Series Hardware Installation Guide.
The management port of the CSC SSM must be connected to your network to allow management of and automatic updates to the CSC SSM software. Additionally, the CSC SSM uses the management port for email notifications and syslogging.
With the CSC SSM, you should have received a Product Authorization Key (PAK). Use the PAK to register the CSC SSM at the following URL.
http://www.cisco.com/go/license
After you register, you will receive activation keys by email. The activation keys are required before you can complete Step 6
Gather the following information, for use in Step 6.
• Activation keys, received after completing Step 2.
• SSM management port IP address, netmask, and gateway IP address.
Continue reading here: Getting Started with the Csc Ssm
Was this article helpful?