<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5512X in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5512x/m-p/2483429#M45632</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been on and off this project for a month but hopfully will have the next week or two to focus on it.&lt;/P&gt;&lt;P&gt;I have a cisco ASA 5512X and i'm trying to get the IPS working.&lt;/P&gt;&lt;P&gt;Looking on google and cisco forums it says you need a management interface. We do not use the management interface we just have the lan port of the ASA plugged direct into our LAN switch.&lt;/P&gt;&lt;P&gt;few questions i need clearing up.&lt;/P&gt;&lt;P&gt;1. Do i need to use the management interface? If i do, do a need to route it to my internal lan as we only plug into a switch not a layer 3 device to do any routing?&lt;/P&gt;&lt;P&gt;2. Can i not just use my inside interface?&lt;/P&gt;&lt;P&gt;3. When the above is complete do i need to use the MPF to route all traffic to the IPS? if so can i use an ACL any any on the outside interface?&lt;/P&gt;&lt;P&gt;I want to check traffic coming from the internet to my LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have looked at &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ips_qsg.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ips_qsg.html&lt;/A&gt; and still cannot get it working. The way i have tested is my enabling all the signatures based on icmp/ping sweep. when i test from the outisde i look at the IPS logs and get nothing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help on this would be great.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:10:45 GMT</pubDate>
    <dc:creator>James Hoggard</dc:creator>
    <dc:date>2019-03-10T13:10:45Z</dc:date>
    <item>
      <title>ASA 5512X</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x/m-p/2483429#M45632</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been on and off this project for a month but hopfully will have the next week or two to focus on it.&lt;/P&gt;&lt;P&gt;I have a cisco ASA 5512X and i'm trying to get the IPS working.&lt;/P&gt;&lt;P&gt;Looking on google and cisco forums it says you need a management interface. We do not use the management interface we just have the lan port of the ASA plugged direct into our LAN switch.&lt;/P&gt;&lt;P&gt;few questions i need clearing up.&lt;/P&gt;&lt;P&gt;1. Do i need to use the management interface? If i do, do a need to route it to my internal lan as we only plug into a switch not a layer 3 device to do any routing?&lt;/P&gt;&lt;P&gt;2. Can i not just use my inside interface?&lt;/P&gt;&lt;P&gt;3. When the above is complete do i need to use the MPF to route all traffic to the IPS? if so can i use an ACL any any on the outside interface?&lt;/P&gt;&lt;P&gt;I want to check traffic coming from the internet to my LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have looked at &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ips_qsg.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ips_qsg.html&lt;/A&gt; and still cannot get it working. The way i have tested is my enabling all the signatures based on icmp/ping sweep. when i test from the outisde i look at the IPS logs and get nothing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help on this would be great.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x/m-p/2483429#M45632</guid>
      <dc:creator>James Hoggard</dc:creator>
      <dc:date>2019-03-10T13:10:45Z</dc:date>
    </item>
    <item>
      <title>Hi james,ASA 5512-X run the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x/m-p/2483430#M45634</link>
      <description>&lt;P&gt;Hi james,&lt;/P&gt;&lt;P&gt;ASA 5512-X run the IPS module as a software module, and the IPS management interface shares the Management 0/0 interface with the ASA.&lt;/P&gt;&lt;P&gt;1. You need&amp;nbsp; to use mgt0/0 interface , You must remove the ASA-configured name for Management 0/0 and configure IPS address from one of the ASA inside network, just plug it in your switch.&lt;/P&gt;&lt;P&gt;3. Yes, you need MPF to route traffic to the IPS module. You need not to open any to any ACL on the outside interface as it will be a huge security hole.&lt;/P&gt;&lt;P&gt;Create an ACL with the desired traffic to be inspected by IPS.&lt;/P&gt;&lt;P&gt;In your case use ACL with source any destination to your LAN network and match it under class map.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;"Please rate helpful posts"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Apr 2014 10:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x/m-p/2483430#M45634</guid>
      <dc:creator>Poonam Garg</dc:creator>
      <dc:date>2014-04-09T10:45:56Z</dc:date>
    </item>
  </channel>
</rss>

