<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Hi in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hi/m-p/2041130#M54482</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;interface Management0/0&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no nameif management&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;security-level 100&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no ip address&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;management-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also set on the IPS the default gateway to be the inside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then give it a try,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Oct 2012 23:11:08 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-10-23T23:11:08Z</dc:date>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/hi/m-p/2041129#M54481</link>
      <description>&lt;P&gt;Hello i have a problem i dont know whats going on ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; i have 5555-x ips ssp , the initial configuration has been done and i can see that the ip address is the same subnet as the inside interface of the firewall , still i can not ping the ips from the network of access it from the web interface. the managment interface connected to the network here are the config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.6(1)2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname STCFW&lt;/P&gt;&lt;P&gt;domain-name seu.net&lt;/P&gt;&lt;P&gt;enable password pyAlZEs.R9HXocav encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 2.2.2.2 255.255.255.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1.60&lt;/P&gt;&lt;P&gt; vlan 60&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.60.10 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/4&lt;/P&gt;&lt;P&gt; description LAN Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/7&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa861-2-smp-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name seu.net&lt;/P&gt;&lt;P&gt;object network PAT&lt;/P&gt;&lt;P&gt; host 2.2.2.2&lt;/P&gt;&lt;P&gt;object network Inside&lt;/P&gt;&lt;P&gt; range 10.0.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list 101 extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list any extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside 10.1.20.12&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface failover GigabitEthernet0/4&lt;/P&gt;&lt;P&gt;failover polltime unit 1 holdtime 3&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover interface ip failover 10.0.61.1 255.255.255.0 standby 10.0.61.2&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-66114.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network Inside&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic pat-pool interface dns&lt;/P&gt;&lt;P&gt;access-group any in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 2.2.2.2 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.0.60.1 1&lt;/P&gt;&lt;P&gt;route inside 10.1.72.0 255.255.255.0 10.0.60.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;http 10.1.20.12 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;http 10.0.0.0 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh 10.0.0.0 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 15&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tls-proxy maximum-session 1000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;ssl encryption des-sha1&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username seu password ev3A2EZ.qpv5wwM6 encrypted&lt;/P&gt;&lt;P&gt;username cisco password yYLyBrxx5SXkticB encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:f8b62a75b25a0d034884fb3cc979ea45&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;STCFW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IPS: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;B-IPS-Active# sh configuration&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;! Current configuration last modified Tue Oct 23 07:18:05 2012&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;! Version 7.1(4)&lt;/P&gt;&lt;P&gt;! Host:&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Realm Keys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key1.0&lt;/P&gt;&lt;P&gt;! Signature Definition:&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Update&amp;nbsp;&amp;nbsp;&amp;nbsp; S615.0&amp;nbsp;&amp;nbsp; 2012-01-03&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service interface&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service authentication&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service event-action-rules rules0&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service host&lt;/P&gt;&lt;P&gt;network-settings&lt;/P&gt;&lt;P&gt;host-ip 10.0.60.9/24,10.0.60.1&lt;/P&gt;&lt;P&gt;host-name B-IPS-Active&lt;/P&gt;&lt;P&gt;telnet-option enabled&lt;/P&gt;&lt;P&gt;access-list 10.0.0.0/24&lt;/P&gt;&lt;P&gt;dns-primary-server disabled&lt;/P&gt;&lt;P&gt;dns-secondary-server disabled&lt;/P&gt;&lt;P&gt;dns-tertiary-server disabled&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;time-zone-settings&lt;/P&gt;&lt;P&gt;offset 0&lt;/P&gt;&lt;P&gt;standard-time-zone-name UTC&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service logger&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service network-access&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service notification&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service signature-definition sig0&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service ssh-known-hosts&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service trusted-certificates&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service web-server&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service anomaly-detection ad0&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service external-product-interface&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service health-monitor&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service global-correlation&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service aaa&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service analysis-engine&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;B-IPS-Active#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ips can not ping anything even the GW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please assist &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:48:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hi/m-p/2041129#M54481</guid>
      <dc:creator>mohammedhabib</dc:creator>
      <dc:date>2019-03-10T12:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Hi</title>
      <link>https://community.cisco.com/t5/network-security/hi/m-p/2041130#M54482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;interface Management0/0&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no nameif management&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;security-level 100&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no ip address&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;management-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also set on the IPS the default gateway to be the inside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then give it a try,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 23:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hi/m-p/2041130#M54482</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-23T23:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Hi</title>
      <link>https://community.cisco.com/t5/network-security/hi/m-p/2041131#M54483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; still i am unable to reach the IPS SSP (ping,http or https), here are the configration &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Card Type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA 5555-X IPS Security Services Processor&lt;/P&gt;&lt;P&gt;Model:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA5555-IPS&lt;/P&gt;&lt;P&gt;Hardware version:&amp;nbsp;&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;Serial Number:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FCH1629797V&lt;/P&gt;&lt;P&gt;Firmware version:&amp;nbsp;&amp;nbsp; N/A&lt;/P&gt;&lt;P&gt;Software version:&amp;nbsp;&amp;nbsp; 7.1(4)E4&lt;/P&gt;&lt;P&gt;MAC Address Range:&amp;nbsp; d48c.b54e.514e to d48c.b54e.514e&lt;/P&gt;&lt;P&gt;App. name:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS&lt;/P&gt;&lt;P&gt;App. Status:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up&lt;/P&gt;&lt;P&gt;App. Status Desc:&amp;nbsp;&amp;nbsp; Normal Operation&lt;/P&gt;&lt;P&gt;App. version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7.1(4)E4&lt;/P&gt;&lt;P&gt;Data Plane Status:&amp;nbsp; Up&lt;/P&gt;&lt;P&gt;Status:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Up&lt;/P&gt;&lt;P&gt;License:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS Module&amp;nbsp; Enabled&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Mgmt IP addr:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.60.9&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Mgmt Network mask:&amp;nbsp; 255.255.255.0&lt;/P&gt;&lt;P&gt;Mgmt Gateway:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.60.10 ===&amp;gt; this is the ASA inside interface&lt;/P&gt;&lt;P&gt;Mgmt Access List:&amp;nbsp;&amp;nbsp; 0.0.0.0/0&lt;/P&gt;&lt;P&gt;Mgmt Access List:&amp;nbsp;&amp;nbsp; 10.0.0.0/24&lt;/P&gt;&lt;P&gt;Mgmt web ports:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 443&lt;/P&gt;&lt;P&gt;Mgmt TLS enabled:&amp;nbsp;&amp;nbsp; true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if any one has configured this IPS SSP before please share your config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 11:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hi/m-p/2041131#M54483</guid>
      <dc:creator>mohammedhabib</dc:creator>
      <dc:date>2012-10-24T11:17:56Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/hi/m-p/2041132#M54485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so far i can use the direct connection to the MNG interface and this was success , but when i connect the MNG interface to a switch Layer2 and connect my PC to the other port in the switch , i can not ping the MNG interface .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think there is some configuration should be done in the MNG interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am looking for it and if some one knows how to do it it will help alot . thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 13:39:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hi/m-p/2041132#M54485</guid>
      <dc:creator>mohammedhabib</dc:creator>
      <dc:date>2012-10-24T13:39:17Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/hi/m-p/2041133#M54486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Mohammed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be a layer 2 problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me send you what needs to be done to make this happen:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H4 style="color: #000000; font-size: 12px;"&gt;Best practice for setup for IPS and ASA management&lt;/H4&gt;&lt;OL style="color: #000000; font-size: 12px;" type="1"&gt;&lt;LI&gt;IPS and ASA management cannot both be accessed through the Management 0/0 interface.&lt;/LI&gt;&lt;LI&gt;No nameif is assigned to the ASA Management 0/0 interface. ASA management is accessed on traffic bearing interfaces.&lt;/LI&gt;&lt;LI&gt;The IPS is given an IP address reachable from the “inside” nameif.&lt;/LI&gt;&lt;LI&gt;Access from the “inside” occurs through either switching or routing, without involving the ASA.&lt;/LI&gt;&lt;LI&gt;In order to allow management from the outside, create a static NAT translation for the sensor IP address or define port forwarding to the appropriate port (port redirection is used in this example).&lt;/LI&gt;&lt;/OL&gt;&lt;P style="color: #000000; font-size: 12px;"&gt;In this scenario, the IPS management communications to the outside network behaves similar to any other host on the inside network. This is used for signature updates, Global Correlation and IPS Service License requests.&lt;/P&gt;&lt;P style="color: #000000; font-size: 12px;"&gt;&lt;IMG alt="ips-config-mod-01.gif" border="0" src="http://www.cisco.com/image/gif/paws/113690/ips-config-mod-01.gif" usemap="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd5d03.shtml" /&gt;&lt;/P&gt;&lt;P style="color: #000000; font-size: 12px;"&gt;Configuration:&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: arial, helvetica, sans-serif; font-size: 12px;"&gt;&lt;PRE style="font-size: 15.199999809265137px;"&gt;interface GigabitEthernet0/0
 nameif outside
 security-level 0
 ip address 192.168.3.1 255.255.0.0
!
interface GigabitEthernet0/1
 nameif inside
 security-level 0
 ip address 192.168.1.1 255.255.255.0
!
interface Management0/0
 no nameif
 security-level 0
 management-only
!
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object network IPS-management
 host 192.168.1.2
object network ASA-inside
 host 192.168.1.1
object-group service HTTP
 service-object tcp-udp destination eq www
 service-object tcp destination eq https
access-list global_access extended permit ip any any
access-list global_access_1 remark Allow IPS management out through to the internet.
access-list global_access_1 extended permit object-group HTTP object IPS-management any

 nat (inside,outside) source dynamic IPS-management IPS-management interface

static (outside,inside) TCP 192.168.3.1 65432 192.168.1.2 https&amp;nbsp; netmask&amp;nbsp; 255.255.255.255
! Use of an ephemeral port allows for the use of common ports for other network applications.&amp;nbsp; 
This also conceals the actual management port by making it not well known.
 
ASA# show module ips details | include Mgmt
 
Mgmt IP addr:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.2
Mgmt Network mask:&amp;nbsp; 255.255.255.0
Mgmt Gateway:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1
Mgmt Access List:&amp;nbsp;&amp;nbsp; 0.0.0.0/0
Mgmt web ports:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 443
Mgmt TLS enabled:&amp;nbsp;&amp;nbsp; true&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 16:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hi/m-p/2041133#M54486</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-24T16:59:59Z</dc:date>
    </item>
  </channel>
</rss>

