Aipssm Module
The Cisco ASA Security Appliance series supports the Advanced Inspection and Protection Security Service Module (AIP-SSM). The AIP-SSM comes in two modules: the AIP-SSM-10 and the AIP-SSM-20. Both modules function the same way, support the same features, and look identical. The only difference between the two modules is the processor speed and memory size of the AIP-SSM-20, which is faster and larger than that of the AIP-SSM-10. The AIP-SSM uses two physical channels to communicate with the Security Appliance. All Intrusion Protection System (IPS) packets transmit through a Gigabit Ethernet interface that connects the AIP-SSM to the Security Appliance. A second connection that handles the control traffic between the module and the Security Appliance transmits through an internal 10/100 Ethernet interface. The AIP-SSM module also contains an external 10/100/1000 Ethernet management port that is primarily used for software upgrades and Cisco Adaptive Security Device Manager (ASDM) management access. The AIP-SSM can analyze the traffic flow through the packet content by opening the packet envelope as well as the payload, allowing it to inspect Layers 3 to 7.
The AIP-SSM can monitor the traffic flow in two ways. In promiscuous mode, the AIP-SSM takes a copy of the traffic flow and inspects the copy of the traffic instead of the live traffic flow. This eliminates the chance that the inspection will affect the actual flow of traffic on the Security Appliance, as it is never actually touched. This will reduce the effectiveness of the IPS services, since the AIP-SSM will not be able to react to the traffic flow instantly and may allow malicious packets through before the AIP-SSM intervenes with the assigned action for the attack. To directly prevent attacks through the AIP-SSM, the in-line mode must be enabled.
Inline mode directly monitors and inspects the live traffic flows through the Security Appliance. If an attack is detected, the packets that the inspection found as malicious, as well as all other packets in that traffic flow, are "stopped" by the AIP-SSM before they enter the network.
Like the Security Appliance, the AIP-SSM supports a failover configuration that handles how the Security Appliance permits traffic. In a failed-open mode, the Security Appliance will continue to transmit traffic flows without IPS inspection and possibly will allow malicious packets through unhindered. The AIP-SSM can also fail-closed, which will drop all traffic flows that have been configured to use the AIP-SSM IPS service. This means that all traffic that must pass through the AIP-SSM will stop at the Security Appliance until the AIP-SSM is enabled again.
Installing the AIP-SSM Module
After the AIP-SSM module has been installed into the Security Appliance, you must verify that the software used by the AIP-SSM for IPS services is functional. You can do this by using the show module 1 detail command in privileged mode on the Security Appliance. The output of the command, shown in Example 19-8, displays the status of the modules, firmware version, and software version. If the IPS software is missing or corrupt, the software version will not be displayed.
|
Getting details |
from the Service Module, please wait... |
|
Unable to read details from slot 1 |
|
|
ASA 5500 Series |
Security Services Module-10 |
|
Model: |
|
|
Hardware version |
: 1.0 |
|
Serial Number: |
12345678 |
|
Firmware version |
: 1.0(7)2 |
|
Software version |
|
|
Status: |
Init |
The Status field displays the current status of the module and can have the following states:
■ Initializing—The module has been recognized and is in the process of being initialized with the system.
■ Up—The module is online and functioning properly.
■ Unresponsive—The Security Appliance cannot communicate with the module.
■ Reloading—The module is reloading.
■ Shutting—The module is in the process of shutting down.
■ ShuttingDown—The module has completed the shutdown procedures and is offline.
■ Recover—The module is attempting to download a recovery image.
In Example 19-8, you will notice that the software version is not displayed. The reason is that the AIP-SSM cannot read the IPS image due to corruption or nonexistence. To resolve this, the AIP-SSM module requires a new IPS image from which to initialize. The Security Appliance uses the hw-module module 1 recover command to define where to download an IPS image file from a TFTP server. To manually specify the TFTP server, filename, and network configurations, you can add the configure keyword to the preceding command, as shown in Example 19-9.
Example 19-9 TFTP an IPS Image
|
PIXfirewall(config)# |
hw-module module 1 |
recover configure |
|
|
Image URL [tftp://0.i |
5.0.0/]: tftp://192 |
168.10.3/AIP-SSM-K9-sys-1.1-a-5.0 |
0.22.img |
|
Port IP Address [0.0 |
0.0]: |
||
|
VLAN ID [0]: |
|||
|
5.0.0]: |
Once you have defined the TFTP server and IPS image, you must download and load the new image onto the AIP-SSM and reboot the module. Use the hw-module 1 recover boot command to start this process. This will download the image from the defined TFTP server and then attempt to boot and initialize the AIP-SSM module with the new image. You can view the process in detail by using the module-boot debug command preceding the hw-module 1 recover boot command, as shown in Example 19-10.
Example 19-10 module-boot debug Output
PIXfirewall (config)# module-boot debug debug module-boot enabled at level 1
PIXfirewall (config)# hw module 1 recover boot
The module in slot 1 will be recovered. This may erase all configuration and all data on that device and attempt to download a new image for it.
Recover module in slot 1? [confirm]
Recover issued for module in slot 1
PIXfirewall (config)# %The module in slot 1 is unresponsive. %The module in slot 1 is recovering.
Slot-1 8> tftp [email protected]
Slot-1 9> !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!
%The module in slot 1 is recovering. Slot-1 10>
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!
Slot-1 79> !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Slot-1 80> Received 23140374 bytes
Slot-1 81> Launching TFTP Image...
%The module in slot 1 is recovering.
%The module in slot 1 is recovering.
%The module in slot 1 is recovering.
%The module in slot 1 is recovering.
Slot-1 82> Launching BootLoader...
%The module in slot 1 is recovering.
%The module in slot 1 is recovering.
After this is complete, use the show module 1 command again to verify that the module initialized correctly, as shown in Example 19-11.
|
PIXfirewall(config)# show module 1 Mod Card Type |
Model |
Serial No. |
|
1 ASA 5500 Series Security Services Module-10 Mod MAC Address Range Hw Version |
ASA-SSM-10 Fw Version |
12345678 Sw Version |
|
1 000b.fcf8.0170 to 000b.fcf8.0170 1.0 Mod Status |
1.0(7)2 |
5.0(0.22)S129.0 |
|
1 Up |
Setting Up the AIP-SSM Module
Now that you have a working IPS image on the AIP-SSM, you must perform an initial configuration setup on the module. The setup process can be done through the command-line interface (CLI) of the AIP-SSM module. To access the module's CLI, telnet to the module using the session 1 command in privileged mode on the Security Appliance. When you use this command, you will telnet to the module and be prompted for a username and password to gain access to the CLI. Since this will be the first time you have accessed the module, you must use the default username and password, which are cisco and cisco, respectively. Immediately after you enter the password, the module will prompt you to enter a new password for the username cisco. This will replace the default password for the module.
You can now run the setup command, which will allow the administrator to configure the basic AIP-SSM settings, including the hostname, IP interfaces, Telnet server, web server port, access control lists (ACL), and time settings. The module will initially display the current configuration of the module, which should be the default settings. The next section will allow you to modify each attribute that you may need changed, such as the IP address or ACLs, as shown in Example 19-12.
Example 19-12 Configuring Basic AIP-SSM Settings sensor# setup
— System Configuration Dialog —
Current Configuration:
service host network-settings host-ip 10.1.9.201/24,10.1.9.1
host-name sensor telnet-option disabled ftp-timeout 300
Example 19-12 Configuring Basic AIP-SSM Settings (Continued)
login-banner-text exit time-zone-settings offset 0
standard-time-zone-name UTC exit summertime-option disabled ntp-option disabled exit service web-server port 443
exit
Continue with configuration dialog?[yes]: <yes> Enter host name[sensor]: sensor1
Enter IP interface[192.168.10.31/24,192.168.10.1]: 192.168.10.41/24,198.168.10.1
Enter telnet-server status[disabled]:
Enter web-server port[443]:
Modify current access list?[no]: yes
Current access list entries:
No entries
Permit: 192.168.10.0/24 Permit:
[0] Go to the command prompt without saving this config.
[1] Return back to the setup without saving this config.
[2] Save this configuration and exit setup. Enter your selection[2]: 2
Warning: Reboot is required before the configuration change will take effect Configuration Saved.
Warning: The node must be rebooted for the changes to go into effect. Continue with reboot? [yes]: yes
The attributes that you can change are these:
■ Hostname—You can use this attribute to change the hostname of the module. The hostname can be no longer than 64 characters.
■ IP Interface—You can use this attribute to set the IP address of the external 10/100/100 Ethernet port.
■ Telnet Server—You can enable this attribute if you wish to allow a remote user Telnet access to the module. Since Telnet is not a secure terminal application, it is recommended that this attribute be disabled at all times.
■ Web Server—You can use this attribute to set the TCP port for the internal web server. The default is 443 (HTTPS).
■ Modify Current Access List—You can use this attribute list to input hosts or networks that can have access to the module through remote ASDM or Telnet connections.
Continue reading here: Configuring IPS Through ASDM
Was this article helpful?