<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA IPS Transparent Design Solution Needed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395872#M53191</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Bob, when you say IPS outside the firewall do you mean IPS not integrated with ASA? Correct me if I am wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the best option will be to replace the asa firewals and implement 5520 asa pair with asa ips on the asa-x series firewall? What are the other options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also on the design issue, if I implement asa ips with promiscous&amp;nbsp; mode/fail open (more of a IDS) and the firewall in transparent mode, is it going to affect the existing asa ha pair?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Dec 2013 18:15:31 GMT</pubDate>
    <dc:creator>avilt</dc:creator>
    <dc:date>2013-12-02T18:15:31Z</dc:date>
    <item>
      <title>ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395870#M53189</link>
      <description>&lt;P&gt;I have a query on IPS deployment. I have a customer with the following setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One Internel Cisco L3 switch connects to ---&amp;gt; Two 5520 ASA firwalls in HA mode active/standby connects to another privae network.&lt;/P&gt;&lt;P&gt;Now I am asked to put a ASA 5525-X series IPS between the L3 switch &amp;amp; &lt;SPAN style="font-size: 10pt;"&gt;---&amp;gt; Two ASA firwalls.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;What are the implementation options available with out touching any config on L3 switch or t&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;wo 5520 ASA firwalls&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can I set this up in a transparent mode?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395870#M53189</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2019-03-10T13:06:17Z</dc:date>
    </item>
    <item>
      <title>ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395871#M53190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first design issue is that you are being asked to place an IPS sensor OUTSIDE the firewall?&lt;/P&gt;&lt;P&gt;Is anyone actually going to be looking into the events being generated (event analysis), if so placing your sensor outside the firewall is a terrible idea becuse you will be generating IPS events on traffic that very well may be blocked by the firewall behind it. This will waste the resources and bandwidth of the person(s) doing event analysis.&lt;/P&gt;&lt;P&gt;The second issue is Realibility. You have an HA pair of 5520s, that tells me someone thinks connectivity is important to invest in redundant firewalls. You are going to definitely lower the realibility of this design by placing a single device that will be updated frequently and even rebooted (software updates). An IPS sensor does not have the realibility of a switch.&lt;/P&gt;&lt;P&gt;The good news is that the IPS sensors are all Layer 2 devices and do not require any changes to your existing Layer 3 design.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 15:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395871#M53190</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2013-12-02T15:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395872#M53191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Bob, when you say IPS outside the firewall do you mean IPS not integrated with ASA? Correct me if I am wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the best option will be to replace the asa firewals and implement 5520 asa pair with asa ips on the asa-x series firewall? What are the other options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also on the design issue, if I implement asa ips with promiscous&amp;nbsp; mode/fail open (more of a IDS) and the firewall in transparent mode, is it going to affect the existing asa ha pair?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 18:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395872#M53191</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2013-12-02T18:15:31Z</dc:date>
    </item>
    <item>
      <title>ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395873#M53192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; You orginaly stated that you wanted to place an ASA5525-X between the external L3 switch and a HA pair of existing ASA5520 firewalls. That would place the ASA5525-X on the exterior of your HA firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "best option" depends on cost and product support.&lt;/P&gt;&lt;P&gt;Replacing your ASA5520 firewalls with 5525-X firewalls seems like an expensive way to get IPS functionality&lt;/P&gt;&lt;P&gt;You could find some AIP-SSM modules. End of sale was March 2013, so you'll have to buy some used. Put them into your existing 5520s. You can still get almost 5 years of licensing and support form Cisco on them: &lt;A href="http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/eol_C51-727284.html"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/eol_C51-727284.html&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even an ASA with an IPS feature (either in software or hardware) in promiscuous mode will still interrupt traffic if you are passing traffic thru it upon some failures. They way around that would be to use a Tap or doing a spanning port on your L3 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternately you could place an inline IPS in the stream of traffic with an external FailOpen switch to divert traffic around an IPS sensor that is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Dec 2013 21:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395873#M53192</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2013-12-02T21:26:00Z</dc:date>
    </item>
    <item>
      <title>ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395874#M53193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bob, sorry correction, I would like to place asa IPS behind&lt;STRONG&gt; internal&lt;/STRONG&gt; L3 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;First the ASA pair and then internal L3 switch. I need to place the ASA-5525-X-IPS&amp;nbsp; in between them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Customer does not allow me to touch the existing setup. So what are the available options for me?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 14:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395874#M53193</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2013-12-03T14:16:01Z</dc:date>
    </item>
    <item>
      <title>ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395875#M53194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Avit -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you read my responses carefully, you'll find all the answers to your question of available options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 16:42:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395875#M53194</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2013-12-03T16:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395876#M53195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you dont mind&amp;nbsp; could please exlain the following setup. Attached is my setup diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;1) They way around that would be to use a Tap or doing a spanning port on your L3 switch.&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;How can I integrate this with ASA IPS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;2) Alternately you could place an inline IPS in the stream of traffic with an external FailOpen switch to divert traffic around an IPS sensor that is down.&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;What is external fail open?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Dec 2013 17:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395876#M53195</guid>
      <dc:creator>avilt</dc:creator>
      <dc:date>2013-12-03T17:02:43Z</dc:date>
    </item>
    <item>
      <title>ASA IPS Transparent Design Solution Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395877#M53196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You ask a lot of questions without providing any detailed information.&lt;/P&gt;&lt;P&gt;ASSUMING your L3 switch is a Cisco product, you can configure "Port Spanning" to grab a copy of your traffic and send it to that ASA running as a IDS.&lt;/P&gt;&lt;P&gt;I'll let you look up the configuration guide for your specific switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco does not sell fail open switches. You can either make one yourself from a L2 switch (search the forum for clues) or buy one from a variety of vendors (another search will be required)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 18:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ips-transparent-design-solution-needed/m-p/2395877#M53196</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2013-12-04T18:07:10Z</dc:date>
    </item>
  </channel>
</rss>

