<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 9.X Routed + Transparent + Active Acitve + IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217544#M350012</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marvin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 May 2013 12:09:53 GMT</pubDate>
    <dc:creator>Dumpster Eightyeight</dc:creator>
    <dc:date>2013-05-22T12:09:53Z</dc:date>
    <item>
      <title>ASA 9.X Routed + Transparent + Active Acitve + IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217540#M350008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently looking at design models for a Multi-Tenancy solution.&lt;/P&gt;&lt;P&gt;The firewall layer will be 2 X ASA's running 9.X to take advantage of VPN's in multiple context mode and mixed L3 and L2 contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will be delivering services through multiple L3 contexts (between 2 and 5 L3 contexts for services) and 1 transparent context for customers infrastructure&amp;nbsp; who will then have virtual firewalls for NAT's and VPN's etc withing their own environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not very experienced with IPS so my query is; if we were to get an IPS license for both ASA's how would the IPS fit in, can we use it to inspect traffic for all the L3 contexts and the transparent context?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice or doc's around this would be brilliant, thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217540#M350008</guid>
      <dc:creator>Dumpster Eightyeight</dc:creator>
      <dc:date>2019-03-12T01:42:29Z</dc:date>
    </item>
    <item>
      <title>ASA 9.X Routed + Transparent + Active Acitve + IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217541#M350009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In a multi-context X series ASA you use the allocate-ips command. Reference more details &lt;A href="http://www.cisco.com/en/US/docs/security/ips/7.1/configuration/guide/cli/cli_asa_ips.html#wp1084903"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One shortcoming is that in an ASA HA setup the two IPSs don't know about each other so you need to synchronize their configurations either manually of via policies using something like the the free &lt;A href="http://www.cisco.com/en/US/products/ps9610/index.html"&gt;IPS Manager Express&lt;/A&gt; (IME) tool or, for larger setups, the licensed &lt;A href="http://www.cisco.com/en/US/products/ps6498/index.html"&gt;CSM product&lt;/A&gt;. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 21:47:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217541#M350009</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-05-13T21:47:44Z</dc:date>
    </item>
    <item>
      <title>ASA 9.X Routed + Transparent + Active Acitve + IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217542#M350010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marvin, that's brilliant thanks for the link, I have found a lot of what I need to know like the ability to create Virtual Sensors (up to 4) and being able to assign the same Virtual Sensor to more than one context so that's great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have noticed in my research that the max throguhput drops significantly when using IPS - for the 5525 it goes from 1Gbps - 2 Gbps down to 600Mbps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't suppose you know, if I have assigned a Virtual Sensor to a transparent context where I have multiple tenants going through it, if I have one of those customers that is going through this transparent context that opts out of requiring IPS will their traffic still go through it but through a sort of pass all traffic policy and so hitting/contributing to the max 6000Mbps throughput or will their traffic not hit the IPS at all thus opening up the max throughput back to what the ASA is capable of...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this makes sense!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 14:20:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217542#M350010</guid>
      <dc:creator>Dumpster Eightyeight</dc:creator>
      <dc:date>2013-05-14T14:20:18Z</dc:date>
    </item>
    <item>
      <title>ASA 9.X Routed + Transparent + Active Acitve + IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217543#M350011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're welcome. Thanks for the rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think once you assign a context to the IPS module you will be effectively throttling all the traffic via that context to the IPS's limit (600 Mbps on a 5525X, shared across all the assigned contexts).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 May 2013 15:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217543#M350011</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-05-14T15:12:03Z</dc:date>
    </item>
    <item>
      <title>ASA 9.X Routed + Transparent + Active Acitve + IPS</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217544#M350012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Marvin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 12:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-x-routed-transparent-active-acitve-ips/m-p/2217544#M350012</guid>
      <dc:creator>Dumpster Eightyeight</dc:creator>
      <dc:date>2013-05-22T12:09:53Z</dc:date>
    </item>
  </channel>
</rss>

