Cisco Systems and the ASA Services Module Manual De Usuario

Descargar
Página de 712
 
31-13
Cisco ASA Series Firewall CLI Configuration Guide
 
Chapter 31      Configuring the ASA IPS Module
  Configuring the ASA IPS module
(ASA 5510 and Higher) Configuring Basic Network Settings
Session to the module from the ASA and configure basic settings using the setup command.
Note
(ASA 5512-X through ASA 5555-X) If you cannot session to the module, then the IPS module is not 
running. See the 
, and then repeat this procedure after you install the module.
Detailed Steps
(ASA 5505) Configuring Basic Network Settings
An ASA IPS module on the ASA 5505 does not have any external interfaces. You can configure a VLAN 
to allow access to an internal IPS management IP address over the backplane. By default, VLAN 1 is 
enabled for IPS management. You can only assign one VLAN as the management VLAN. This section 
describes how to change the management VLAN and IP address if you do not want to use the default, 
and how to set other required network parameters.
Note
Perform this configuration on the ASA 5505, not on the ASA IPS module.
Prerequisites
When you change the IPS VLAN and management address from the default, be sure to also configure 
the matching ASA VLAN and switch port(s) according to the procedures listed in 
Chapter 10, “Starting 
Interface Configuration (ASA 5505),”
 in the general operations configuration guide. You must define 
and configure the VLAN for the ASA so the IPS management interface is accessible on the network.
Command
Purpose
Step 1
Session to the IPS module according to the 
.
Step 2
setup
Example:
sensor# setup
Runs the setup utility for initial configuration of the ASA IPS 
module. You are prompted for basic settings. For the default 
gateway, specify the IP address of the upstream router. See the 
 to understand the requirements for your network. The 
default setting of the ASA management IP address will not work.