Cisco Cisco ASA 5512-X Adaptive Security Appliance

ページ / 12
2
Release Notes for the Cisco ASA 1000V, Version 8.7(x)
  Important Notes
Important Notes
Complete Solution Installation
Neither the ASA 1000V nor VSG supports non-ASCII characters. To support localization, all 
components (that is, Cisco VNMC, Cisco VSG, and ASA 1000V) must meet this requirement.
The ASA 1000V and Cisco VNMC require that the VMware vCenter installation, including 
keyboard and password or shared key settings, be set to American English.
ASA 1000V Installation
You can use only one management mode (either VNMC or ASDM) on the ASA 1000V. They are 
mutually exclusive, and you need to decide on the mode before installation. If you want to switch 
management modes, you must reinstall the ASA 1000V.
ASDM is used to monitor traffic on the ASA 1000V in both VNMC and ASDM modes.
Routes through the management interface can only be configured using the CLI in VNMC mode. 
The VMs that are on the inside of the ASA 1000V need to be directly connected to a Nexus 1000V 
switch and in the same VLAN as the one you have configured on the inside of the ASA 1000V. 
Inside VMs must be layer 2 adjacent to the inside of the ASA 1000V. You cannot have a layer 3 hop, 
as with a physical router, on the inside of the ASA 1000V.
Limitations and Restrictions
The ASA 1000V does not support all features that are supported on ASA appliances. 
unsupported features on the ASA 1000V.
Note
The commands that are associated with an unsupported feature are not available at the ASA 1000V CLI. 
Not all commands that are supported on ASA appliances are available on the ASA 1000V platform.
Table 1
Unsupported Features on the ASA 1000V
Feature
Description
AAA for network access
Not supported.
Active/Active failover and subsecond failover
Not supported.
Authentication using certificates
Not supported.
Shun
Not supported.
Botnet traffic filter
Not supported.
Dynamic DNS
Not supported.
Dynamic routing
Not supported.
GTP/GTPRS (Mobile Service Providers)
Not supported.
HTTP inspection maps for deep-packet inspection Not supported.
Identity firewall
Not supported.
Inbound PAT
Not supported.
IPS and CSC modules
Not supported.