<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: transparent mode with AIP-SSM-20 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490285#M67225</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Jun 2010 18:57:41 GMT</pubDate>
    <dc:creator>smperry</dc:creator>
    <dc:date>2010-06-14T18:57:41Z</dc:date>
    <item>
      <title>transparent mode with AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490283#M67223</link>
      <description>&lt;P&gt;I currently have an ASA5510 in routed mode with an AIP-SSM-20.&lt;/P&gt;&lt;P&gt;There is a requirement to use a fibre optic connection between this ASA and another ASA across campus, so the AIP-SSM will have to be removed and replaced with the SSM-4GE.&amp;nbsp; This part should present no issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, this will remove the IPS device, and I still want to use IPS.&lt;/P&gt;&lt;P&gt;So, what I am thinking is to get another ASA5510, install the AIP-SSM, configure ASA for transparent mode and put it in between the inside of the routed ASA and my LAN.&amp;nbsp; The transparent ASA would be functioning strictly as an IPS appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setup would look something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal LAN &amp;lt;&amp;gt; transparent ASA with IPS &amp;lt;&amp;gt; routed ASA &amp;lt;&amp;gt; WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the AIP-SSM still perform IPS with the ASA in transparent mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to configure the ASA and AIP-SSM such that traffic to/from a particular server completely bypasses the AIP-SSM?&lt;/P&gt;&lt;P&gt;I have a couple of fileservers that generate heavy traffic and could overload the AIP-SSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490283#M67223</guid>
      <dc:creator>smperry</dc:creator>
      <dc:date>2019-03-10T12:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: transparent mode with AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490284#M67224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AFAIR, There is no problem to setup AIP in a transparent firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"An ASA in transparent mode can run an AIP.&amp;nbsp; In the event the AIP fails,&lt;/P&gt;&lt;PRE style="margin: 0em;"&gt;the IPS will fail-open and the ASA will continue to pass traffic.&lt;BR /&gt;However, if an interface or cable fails, then traffic will stop.&amp;nbsp; You&lt;BR /&gt;would need a failover pair to account for this failure event, which&lt;BR /&gt;means another ASA and matching AIP."&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And no there is no problem to exclude certain hosts/ports/subnets from inspection by IPS via MPF.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ips.html#wp1050744"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ips.html#wp1050744&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I however consider however is if the ASAs 5510 as second tier firewall for 5520s will be enough.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html"&gt;http://www.cisco.com/en/US/products/ps6120/prod_models_comparison.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Jun 2010 09:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490284#M67224</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-06-13T09:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: transparent mode with AIP-SSM-20</title>
      <link>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490285#M67225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jun 2010 18:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-mode-with-aip-ssm-20/m-p/1490285#M67225</guid>
      <dc:creator>smperry</dc:creator>
      <dc:date>2010-06-14T18:57:41Z</dc:date>
    </item>
  </channel>
</rss>

