<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yes, that's the high level in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456357#M238653</link>
    <description>&lt;P&gt;Yes, that's the high level approach.&lt;/P&gt;&lt;P&gt;As long as you create your policies based on addresses and keep in mind that you don't have explicit context awareness in PRSM, then you should be fine.&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2014 15:44:39 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-05-08T15:44:39Z</dc:date>
    <item>
      <title>ASA NG 5515-X multicontext support for WSE/AVC and IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456354#M238648</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am designing network security with Cisco ASAs. I have a redundant core / distribution switching in VSS and 2 ASAs (Active / Standby) and trying to evaluate whether I could run multiple security services on one pair of ASA in virtual contexts rather then deploying more ASAs. I need to run DMZ so that it could go in one virtual context, then I need to run WSE, AVC and possibly IPS to protect internal users LANs and also deploy web and application security, here not sure if that is supported in a virtual context and with active/standby setup, apart from that I need to protect the servers with FW rules and IPS, here also a dilemma whether this will work in a virtual context and active / standby setup.&lt;/P&gt;&lt;P&gt;What would you recommend, having separate pair of ASAs for each security service or I could do all that with one pair of ASAs and multi context setup?&lt;/P&gt;&lt;P&gt;Thanks in advance for quick and informative responses.&lt;/P&gt;&lt;P&gt;Remi&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456354#M238648</guid>
      <dc:creator>remi-reszka</dc:creator>
      <dc:date>2019-03-12T04:10:29Z</dc:date>
    </item>
    <item>
      <title>Remi,NGFW services (WSE, AVC</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456355#M238651</link>
      <description>&lt;P&gt;Remi,&lt;/P&gt;&lt;P&gt;NGFW services (WSE, AVC and IPS, depending on your license) are supported on ASAs operating in multi-context mode. The catch is that the NGFW services aren't aware of the contexts per se (as of this time). So you have a single policy set configured in PRSM for a given ASA (or ASA HA pair) that will apply to all your traffic.&lt;/P&gt;&lt;P&gt;Of course, each context has its own service-policy that is used to direct the appropriate traffic to the CX module for inspection and policy enforcement.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 14:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456355#M238651</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-08T14:48:11Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin. So the</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456356#M238652</link>
      <description>&lt;P&gt;Thanks Marvin. So the scenario I am describing would work correct? All I need to do is in PRSM configure various policy-sets and match the traffic globally based on certain rules that would be relevant to certain contexts?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 15:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456356#M238652</guid>
      <dc:creator>remi-reszka</dc:creator>
      <dc:date>2014-05-08T15:18:36Z</dc:date>
    </item>
    <item>
      <title>Yes, that's the high level</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456357#M238653</link>
      <description>&lt;P&gt;Yes, that's the high level approach.&lt;/P&gt;&lt;P&gt;As long as you create your policies based on addresses and keep in mind that you don't have explicit context awareness in PRSM, then you should be fine.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 15:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456357#M238653</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-08T15:44:39Z</dc:date>
    </item>
    <item>
      <title>OK cool. What is the purpose</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456358#M238654</link>
      <description>&lt;P&gt;OK cool. What is the purpose of the explicit context awareness in PRSM? Is it there but still not supported?&lt;/P&gt;&lt;P&gt;The only concern I have is about DMZ on same ASA pair. I guess it should be fine because I would not sent any DMZ traffic to CX module (where it would get mixed up with users or servers traffic) and since DMZ would be on a separate virtual context the security would be maintained. Also the DMZ will be kept on a separate VRF and will need to do VRF leaking from DMZ inside VLAN into servers VLAN in the services VRF.&lt;/P&gt;&lt;P&gt;How about sending both users (for WSE and AVC) and servers (for IPS) traffic into the same CX module? That would work fine?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Remi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 15:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456358#M238654</guid>
      <dc:creator>remi-reszka</dc:creator>
      <dc:date>2014-05-08T15:52:35Z</dc:date>
    </item>
    <item>
      <title>The CX doesn't allow you to</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456359#M238655</link>
      <description>&lt;P&gt;The CX doesn't allow you to use context as an operator for policies. I am not informed on the internals but it obviously knows which context a given flow came from or else it would't know where to put the traffic "back into" the host ASA.&lt;/P&gt;&lt;P&gt;There should be no possibility of traffic co-mingling within the CX. It only acts as a tool to inspect and enforce policy on a given flow and then put it back to the ASA (when appropriate) for egress processing.&lt;/P&gt;&lt;P&gt;FYI you may want to review BRKSEC-2699 from Cisco Live! Milan earlier this year (available from &lt;A href="http://www.ciscolive365.com)" target="_blank"&gt;http://www.ciscolive365.com)&lt;/A&gt;. It has some good explanations about CX policies etc.&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 17:24:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456359#M238655</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-08T17:24:57Z</dc:date>
    </item>
    <item>
      <title>Sounds good, many thanks</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456360#M238656</link>
      <description>&lt;P&gt;Sounds good, many thanks Marvin.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Remi&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2014 22:19:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456360#M238656</guid>
      <dc:creator>remi-reszka</dc:creator>
      <dc:date>2014-05-08T22:19:26Z</dc:date>
    </item>
    <item>
      <title>Hello Marvin,I know we</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456361#M238657</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;&lt;P&gt;I know we already closed this post but could I just ask you something real quick? Whether my ASAs are in active/active or active/standby configuration how about the licensing for WSE/AVC and IPS? Do I but the licensing only for one box or need to purches for each box separately. Can't seem to find much information on that.&lt;/P&gt;&lt;P&gt;Thanks very much in advance.&lt;/P&gt;&lt;P&gt;Remi&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 21:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456361#M238657</guid>
      <dc:creator>remi-reszka</dc:creator>
      <dc:date>2014-05-27T21:40:20Z</dc:date>
    </item>
    <item>
      <title>No problem.Unfortunately you</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456362#M238658</link>
      <description>&lt;P&gt;No problem.&lt;/P&gt;&lt;P&gt;Unfortunately you need licenses on both ASAs for the services to work (for either A/A or A/S mode). The CX modules don't share feature licenses like the base ASA does.&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 22:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456362#M238658</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-27T22:02:09Z</dc:date>
    </item>
    <item>
      <title>I will take it into</title>
      <link>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456363#M238659</link>
      <description>&lt;P&gt;I will take it into consideration, thanks a lot Marvin!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Remi&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2014 22:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ng-5515-x-multicontext-support-for-wse-avc-and-ips/m-p/2456363#M238659</guid>
      <dc:creator>remi-reszka</dc:creator>
      <dc:date>2014-05-27T22:47:27Z</dc:date>
    </item>
  </channel>
</rss>

