<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 Config Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628488#M1023484</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Sushil, I read that document but still have a few questions that maybe you could help me with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could I assign a security-level of 100 to both interfaces and check the box to "allow communications between interfaces with the same security level" or just use the permit any,any access lists?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed instructions exactly to forward all traffic to AIP-SSM for inspection but recieve an error. Here is my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate any input. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACCESS LISTS&lt;/P&gt;&lt;P&gt;ASA5510# sh access-list&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_out extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Outside_access_out extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list IPS extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AIP SSM CONFIG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# access-list IPS permit ip any any&lt;/P&gt;&lt;P&gt;ASA5510(config)# class-map lwc-ips-class&lt;/P&gt;&lt;P&gt;ASA5510(config-cmap)# match access-list IPS&lt;/P&gt;&lt;P&gt;ASA5510(config-cmap)# policy-map lwc-ips-policy&lt;/P&gt;&lt;P&gt;ASA5510(config-pmap)# class lwc-ips-class&lt;/P&gt;&lt;P&gt;ASA5510(config-pmap-c)# ips promiscuous fail-open&lt;/P&gt;&lt;P&gt;ASA5510(config-pmap-c)# service-policy lwc-ips-policy global&lt;/P&gt;&lt;P&gt;ERROR: Policy map global_policy is already configured as a service policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Mar 2007 20:53:55 GMT</pubDate>
    <dc:creator>brobertson</dc:creator>
    <dc:date>2007-03-09T20:53:55Z</dc:date>
    <item>
      <title>ASA 5510 Config Question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628486#M1023479</link>
      <description>&lt;P&gt;We have an ASA 5510 with AIP-SSM10 and will be migrating 515E ruleset in the future. For right now I want to use the ASA behind the PIX as a bridge in order to use the IPS functionality. Would tranparent mode with access lists that allow all traffic both directions work in this situation? I don't want to drop any packets, just mirror traffic to IPS for inspection and alerting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628486#M1023479</guid>
      <dc:creator>brobertson</dc:creator>
      <dc:date>2019-03-11T09:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Config Question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628487#M1023481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi ,&lt;/P&gt;&lt;P&gt;this seems to be a good solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this link gives you extensive information ,how transparent mode works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/fwmode.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/multisec/asa_sw/v_7_2/conf_gd/firewall/fwmode.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it's basicaly "bump in the wire" or " stealth firewall " ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;P&gt;Cisco TAC &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 13:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628487#M1023481</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-09T13:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Config Question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628488#M1023484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply Sushil, I read that document but still have a few questions that maybe you could help me with?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could I assign a security-level of 100 to both interfaces and check the box to "allow communications between interfaces with the same security level" or just use the permit any,any access lists?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I followed instructions exactly to forward all traffic to AIP-SSM for inspection but recieve an error. Here is my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate any input. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACCESS LISTS&lt;/P&gt;&lt;P&gt;ASA5510# sh access-list&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_out extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Outside_access_out extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list IPS extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AIP SSM CONFIG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# access-list IPS permit ip any any&lt;/P&gt;&lt;P&gt;ASA5510(config)# class-map lwc-ips-class&lt;/P&gt;&lt;P&gt;ASA5510(config-cmap)# match access-list IPS&lt;/P&gt;&lt;P&gt;ASA5510(config-cmap)# policy-map lwc-ips-policy&lt;/P&gt;&lt;P&gt;ASA5510(config-pmap)# class lwc-ips-class&lt;/P&gt;&lt;P&gt;ASA5510(config-pmap-c)# ips promiscuous fail-open&lt;/P&gt;&lt;P&gt;ASA5510(config-pmap-c)# service-policy lwc-ips-policy global&lt;/P&gt;&lt;P&gt;ERROR: Policy map global_policy is already configured as a service policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 20:53:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628488#M1023484</guid>
      <dc:creator>brobertson</dc:creator>
      <dc:date>2007-03-09T20:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Config Question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628489#M1023487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could I assign a security-level of 100 to both interfaces and check the box to "allow communications between interfaces with the same security level" or just use the permit any,any access lists? &lt;/P&gt;&lt;P&gt;  ----yes.you can do this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AIP SSM CONFIG &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# access-list IPS permit ip any any &lt;/P&gt;&lt;P&gt;ASA5510(config)# class-map lwc-ips-class &lt;/P&gt;&lt;P&gt;ASA5510(config-cmap)# match access-list IPS &lt;/P&gt;&lt;P&gt;ASA5510(config-cmap)# policy-map lwc-ips-policy &lt;/P&gt;&lt;P&gt;ASA5510(config-pmap)# class lwc-ips-class &lt;/P&gt;&lt;P&gt;ASA5510(config-pmap-c)# ips promiscuous fail-open &lt;/P&gt;&lt;P&gt;ASA5510(config-pmap-c)# service-policy lwc-ips-policy global &lt;/P&gt;&lt;P&gt;ERROR: Policy map global_policy is already configured as a service policy &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;___ans:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config)#   access-list IPS extended permit ip any any&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config)#&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config)# class-map lwc-ips-class&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config-cmap)#  match access-list IPS&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config-cmap)# exit&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config)# policy-map global_policy&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config-pmap)# class lwc-ips-class&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config-pmap-c)#  ips promiscuous fail-open&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config-pmap-c)# exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config-pmap)# exit&lt;/P&gt;&lt;P&gt;ASA-5520-CSC-Standalone(config)# service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH..&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;P&gt;Cisco TAC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2007 21:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-question/m-p/628489#M1023487</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2007-03-09T21:17:39Z</dc:date>
    </item>
  </channel>
</rss>

