<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If your IPS is inline and set in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865440#M43954</link>
    <description>&lt;P&gt;If your IPS is inline and set to fail open then the traffic through the ASA (assuming a standalone ASA and not part of an HA pair) will not be affected when the IPS service module reloads.&lt;/P&gt;
&lt;P&gt;If an ASA is in an HA pair and a service module (ips, cxsc or sfr) fails it will by default trigger a failover event. (ASA 9.5 introduced the option to change that behavior.) The result is the same - zero downtime (although TCP connections may need to re-establish if you don't have stateful failover configured).&lt;/P&gt;</description>
    <pubDate>Tue, 03 May 2016 18:05:22 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-05-03T18:05:22Z</dc:date>
    <item>
      <title>ASA-SSM-20/40 IPS Software upgrade quesiton</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865439#M43953</link>
      <description>&lt;P&gt;I am looking at upgrading the IPS modules (ASA-SSM-20 and ASA-SSM-40) on two different ASA's to ver&amp;nbsp;&lt;SPAN&gt;7.1(11)E4 as per this field notice:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/field-notices/640/fn64080.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/field-notices/640/fn64080.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My question is around whether traffic flowing through the firewall will be impacted during this update and the subsequent reboot of the IPS module.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On the respective ASAs, a service policy is in place that will allow traffic to pass in the case where the IPS module becomes unavailable. &amp;nbsp;Question is, will this in fact happen during the update??&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Suggestions and comments are welcomed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:36:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865439#M43953</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2019-03-10T13:36:35Z</dc:date>
    </item>
    <item>
      <title>If your IPS is inline and set</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865440#M43954</link>
      <description>&lt;P&gt;If your IPS is inline and set to fail open then the traffic through the ASA (assuming a standalone ASA and not part of an HA pair) will not be affected when the IPS service module reloads.&lt;/P&gt;
&lt;P&gt;If an ASA is in an HA pair and a service module (ips, cxsc or sfr) fails it will by default trigger a failover event. (ASA 9.5 introduced the option to change that behavior.) The result is the same - zero downtime (although TCP connections may need to re-establish if you don't have stateful failover configured).&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 18:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865440#M43954</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-05-03T18:05:22Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865441#M43956</link>
      <description>&lt;P&gt;Thanks for your reply Marvin.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The SSM-20 modules are in fact a part of an ASA-5520 HA pair... thanks for mentioning this.&lt;/P&gt;
&lt;P&gt;The SSM-40 is in a standalone ASA-5540.&lt;/P&gt;
&lt;P&gt;Both IPS modules are configured inline.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now regarding the HA pair... I guess I need to manually update each SSM-20 module, is that right? &amp;nbsp;Should I update the secondary ASA/IPS&amp;nbsp;first and then the primary? &amp;nbsp;Or what do you recommend?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 18:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865441#M43956</guid>
      <dc:creator>N3t W0rK3r</dc:creator>
      <dc:date>2016-05-03T18:17:05Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865442#M43957</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;In an HA pair you do need to update each module separately. The service modules operate mostly independently of the parent ASA and have no concept of the HA configuration.&lt;/P&gt;
&lt;P&gt;I would update the secondary first. That will prove to procedure and you can observe it at leisure on the Secondary-Standby unit.&lt;/P&gt;
&lt;P&gt;Once you're happy that it comes back up fine and shows as Ready state you can then force a failover and repeat the upgrade on the unit that's now Primary-Standby.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 18:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ssm-20-40-ips-software-upgrade-quesiton/m-p/2865442#M43957</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-05-03T18:23:51Z</dc:date>
    </item>
  </channel>
</rss>

