<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The management of software in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548796#M237587</link>
    <description>&lt;P&gt;If you haven't seen it already, please review the ASA &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ips_qsg.html"&gt;IPS Module Quick Start Guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;The management of software IPS modules uses the physical management interface of the 5525-X with an IP address that is specified in the setup of the IPS module. This is distinct from any management address you may have setup in the base ASA.&lt;/P&gt;&lt;P&gt;Each IPS will have its own unique IP address.&lt;/P&gt;&lt;P&gt;The IPS modules themselves are not HA-aware and are essentially managed as two independent units. This improves if you move to the NGFW IPS and manage the unit via PRSM on an external server. In that scenario, the HA pair of IPS's are managed as a collective entity&lt;/P&gt;&lt;P&gt;The base ASAs of course share the service policy used to redirect traffic for IPS inspection and (when the service-policy calls for IPS module inspection) also verifies the operational state of the IPS modules as one of the checks done to validate failover status.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jun 2014 20:15:06 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-06-12T20:15:06Z</dc:date>
    <item>
      <title>ASA 5525-X IPS Management IP addresses in HA mode</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548794#M237585</link>
      <description>&lt;P&gt;I am going to install ASA5525-X Firewall in HA mode and both have Software IPS modules and I was wondering how the management IP address will be configured in HA mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is both IPS will have same management IP address?&lt;/P&gt;&lt;P&gt;I looking for some sample config for IPS management IP address configuration in HA mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548794#M237585</guid>
      <dc:creator>dpuranik</dc:creator>
      <dc:date>2019-03-12T04:19:33Z</dc:date>
    </item>
    <item>
      <title>There should not be any big</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548795#M237586</link>
      <description>&lt;P&gt;There should not be any big difference in configuration for management. Even in normal scenario we can have the management access through both the active and stand by IP addresses to the respective devices. All it happens with mac address that uses when it is configured in failover mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 15:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548795#M237586</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-06-12T15:44:20Z</dc:date>
    </item>
    <item>
      <title>The management of software</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548796#M237587</link>
      <description>&lt;P&gt;If you haven't seen it already, please review the ASA &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ips_qsg.html"&gt;IPS Module Quick Start Guide&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;The management of software IPS modules uses the physical management interface of the 5525-X with an IP address that is specified in the setup of the IPS module. This is distinct from any management address you may have setup in the base ASA.&lt;/P&gt;&lt;P&gt;Each IPS will have its own unique IP address.&lt;/P&gt;&lt;P&gt;The IPS modules themselves are not HA-aware and are essentially managed as two independent units. This improves if you move to the NGFW IPS and manage the unit via PRSM on an external server. In that scenario, the HA pair of IPS's are managed as a collective entity&lt;/P&gt;&lt;P&gt;The base ASAs of course share the service policy used to redirect traffic for IPS inspection and (when the service-policy calls for IPS module inspection) also verifies the operational state of the IPS modules as one of the checks done to validate failover status.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 20:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-x-ips-management-ip-addresses-in-ha-mode/m-p/2548796#M237587</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-06-12T20:15:06Z</dc:date>
    </item>
  </channel>
</rss>

