<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 AIP-SSM Layer 2 Mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-aip-ssm-layer-2-mode/m-p/1856232#M55608</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it's mostly possible. We run some of our ASA/AIP-SSM devices like this. The main motivation is the low cost of this bundle. You need to disable as much of the firewall functionality as possible (and some things it does you can't turn off, but they're minor). &lt;/P&gt;&lt;P&gt;If you were planning on making this an in-line sensor, there aren't too many drawbacks (additional ASA OS to babysit, upgrade, additional Ethernet interface for mgmt, etc). But if you wanted to use this as a promiscuous mode IDS you still need to run your traffic thru the box. There is no way to use the ASA with a span port or tap. As a result any outage of the ASA (reboot after you upgraded that OS) will result in a network outage. Reboot that IPS sensor, network outage. (unless you remove the IPS config from the ASA first = PITA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Feb 2012 22:08:36 GMT</pubDate>
    <dc:creator>rhermes</dc:creator>
    <dc:date>2012-02-10T22:08:36Z</dc:date>
    <item>
      <title>ASA 5510 AIP-SSM Layer 2 Mode</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-aip-ssm-layer-2-mode/m-p/1856231#M55607</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been suggested to me that I could use the ASA5510 with an AIP-SSM module to perform full IPS functions in layer 2 only mode behind a Microsoft TMG server firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't require NAT, or any other routing function, just the IPS function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone used the ASA like this?&amp;nbsp; Is it possible? Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kurt&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-aip-ssm-layer-2-mode/m-p/1856231#M55607</guid>
      <dc:creator>Kurt Carlson</dc:creator>
      <dc:date>2019-03-10T12:36:49Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 AIP-SSM Layer 2 Mode</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-aip-ssm-layer-2-mode/m-p/1856232#M55608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it's mostly possible. We run some of our ASA/AIP-SSM devices like this. The main motivation is the low cost of this bundle. You need to disable as much of the firewall functionality as possible (and some things it does you can't turn off, but they're minor). &lt;/P&gt;&lt;P&gt;If you were planning on making this an in-line sensor, there aren't too many drawbacks (additional ASA OS to babysit, upgrade, additional Ethernet interface for mgmt, etc). But if you wanted to use this as a promiscuous mode IDS you still need to run your traffic thru the box. There is no way to use the ASA with a span port or tap. As a result any outage of the ASA (reboot after you upgraded that OS) will result in a network outage. Reboot that IPS sensor, network outage. (unless you remove the IPS config from the ASA first = PITA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Feb 2012 22:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-aip-ssm-layer-2-mode/m-p/1856232#M55608</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2012-02-10T22:08:36Z</dc:date>
    </item>
  </channel>
</rss>

