<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPS Module integration with ASA and basic configuration steps in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982333#M54792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Zubair , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the function of&amp;nbsp; &lt;EM style="text-decoration: underline; "&gt;&lt;STRONG&gt;ips promiscuous fail-close (or fail-open)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/EM&gt;command , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what could be the effect on network if IPS module will be down / stop working &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Aug 2012 01:58:26 GMT</pubDate>
    <dc:creator>aslam.bajwa</dc:creator>
    <dc:date>2012-08-14T01:58:26Z</dc:date>
    <item>
      <title>IPS Module integration with ASA and basic configuration steps</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982331#M54780</link>
      <description>&lt;P&gt;Hi All , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am new in security , i need to integrate IPS module with ASA 5500 and basic configuration steps . so that i can get inside traffic through IPS module to LAN . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please advise some esay steps to perm this activity &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards , &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:45:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982331#M54780</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2019-03-10T12:45:04Z</dc:date>
    </item>
    <item>
      <title>IPS Module integration with ASA and basic configuration steps</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982332#M54785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aslam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will use class maps to divert the traffic to the module. Here are some basic steps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!Identify the traffic that needs to be diverted to the IPS SSP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; access-list IPS permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!Classify the traffic using a class map.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp; class-map IPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; match access-list IPS&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!Specify the action to be taken on the traffic using a policy map. !Since there is already a policy map attached globally in the FW, !the class-map defined above will be added here !only. &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class IPS&lt;/P&gt;&lt;P&gt; ips promiscuous fail-close (or fail-open)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once that is done, the rest of the configuration needs to be done on the IPS using CLI or preferrably the IDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH. Please rate if useful.&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 00:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982332#M54785</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2012-08-14T00:13:19Z</dc:date>
    </item>
    <item>
      <title>IPS Module integration with ASA and basic configuration steps</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982333#M54792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Zubair , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the function of&amp;nbsp; &lt;EM style="text-decoration: underline; "&gt;&lt;STRONG&gt;ips promiscuous fail-close (or fail-open)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/EM&gt;command , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what could be the effect on network if IPS module will be down / stop working &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 01:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982333#M54792</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2012-08-14T01:58:26Z</dc:date>
    </item>
    <item>
      <title>IPS Module integration with ASA and basic configuration steps</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982334#M54795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For failure scenarios, have a look at this. This explains fail open and fail close. Also note that the above command is if you want to setup the IPS in promiscous mode. If you want to put it inline to traffic you need to enter "ips inline fail-close (or fail-open).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/7.1/configuration/guide/cli/cli_ssp.html#wp1086445"&gt;http://www.cisco.com/en/US/docs/security/ips/7.1/configuration/guide/cli/cli_ssp.html#wp1086445&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 02:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982334#M54795</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2012-08-14T02:10:13Z</dc:date>
    </item>
    <item>
      <title>IPS Module integration with ASA and basic configuration steps</title>
      <link>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982335#M54800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks zubair.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 11:33:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-module-integration-with-asa-and-basic-configuration-steps/m-p/1982335#M54800</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2012-08-14T11:33:24Z</dc:date>
    </item>
  </channel>
</rss>

