<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA using only for IPS? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855375#M84765</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is possible to use the ASA with IPS-Module as sensor only, located with her outside-interface on one mirrored switch-port?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 10:57:56 GMT</pubDate>
    <dc:creator>Volker Janusch</dc:creator>
    <dc:date>2019-03-10T10:57:56Z</dc:date>
    <item>
      <title>ASA using only for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855375#M84765</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is possible to use the ASA with IPS-Module as sensor only, located with her outside-interface on one mirrored switch-port?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Volker&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:57:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855375#M84765</guid>
      <dc:creator>Volker Janusch</dc:creator>
      <dc:date>2019-03-10T10:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA using only for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855376#M84772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The outside-interface is for command and control only and can not be used for monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SSM is only able to monitor traffic passing through the ASA.&lt;/P&gt;&lt;P&gt;The ASA does not support connecting it's ports to mirrored switch ports either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The closest you get is to configure the ASA is transparent mode with ACLs on each interface that permit all traffic, and then place the ASA between 2 of your existing devices.  And then place a policy on the ASA to copy all packets to the SSM for promiscuous monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If you have an existing other type of firewall, then you can try placing the transparent ASA between your other firewall and your DMZ switch for example.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All traffic would be passed through the ASA, and be copied to the SSM for promiscuous monitoring.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This mode could best be described as using the ASA as a simulated Tap to send traffic to the SSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2008 16:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855376#M84772</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2008-01-31T16:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA using only for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855377#M84775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a very timely question, as Cisco is recommending the ASA-5510 as a replacement for EOL'ed 4215 sensor. I'm terribly disappointed that the ASA can be run in a promiscuous mode (like the 4215) and must be placed in line. Adding another single point of failure only diminishes overall availability and uptime.&lt;/P&gt;&lt;P&gt;There is no advantage to placing a promiscuous mode IDS device in-line.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2008 20:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855377#M84775</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2008-01-31T20:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA using only for IPS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855378#M84776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, this is the big problem for SMB, because the big IPS-blade is too expansive. And our customer needs at first only the ips-function without the modification of his existing firewall-deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2008 10:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-using-only-for-ips/m-p/855378#M84776</guid>
      <dc:creator>Volker Janusch</dc:creator>
      <dc:date>2008-02-06T10:59:41Z</dc:date>
    </item>
  </channel>
</rss>

