<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA AIP with 2 virtual sensors? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432055#M856667</link>
    <description>&lt;P&gt;i'm green hand in deploying ASA AIP..&lt;/P&gt;&lt;P&gt;Anyone could let me know how to set the following requirements in ASA AIP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Match "ACL1" then sig1 - drop&lt;/P&gt;&lt;P&gt;Match "ACL2" then sig1 - allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this requirements seem need 2 virtual sensors.. however, in ASA AIP, how to do this?&lt;/P&gt;&lt;P&gt;i saw the only way to override action is "high", "medium", "low" , etc..&lt;/P&gt;&lt;P&gt;did any way to set like above requirements?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:54:03 GMT</pubDate>
    <dc:creator>szekahungdanny</dc:creator>
    <dc:date>2019-03-11T17:54:03Z</dc:date>
    <item>
      <title>ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432055#M856667</link>
      <description>&lt;P&gt;i'm green hand in deploying ASA AIP..&lt;/P&gt;&lt;P&gt;Anyone could let me know how to set the following requirements in ASA AIP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Match "ACL1" then sig1 - drop&lt;/P&gt;&lt;P&gt;Match "ACL2" then sig1 - allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this requirements seem need 2 virtual sensors.. however, in ASA AIP, how to do this?&lt;/P&gt;&lt;P&gt;i saw the only way to override action is "high", "medium", "low" , etc..&lt;/P&gt;&lt;P&gt;did any way to set like above requirements?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432055#M856667</guid>
      <dc:creator>szekahungdanny</dc:creator>
      <dc:date>2019-03-11T17:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432056#M856669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi szekahungdanny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are basically two options to achieve this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) You already mentioned, create two virtual sensors, create two class maps maps and assign each class map a different sensor in the policy map. The virtual sensors would have different actions for the specific signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Have one class map and policy action "IPS" and duplicate the signature and assign different attacker/victim filters in the signature definitions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps, rgds, MiKa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 22:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432056#M856669</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2010-06-02T22:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432057#M856671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes. but my difficulty is how to add interface into that virtual sensor..&lt;/P&gt;&lt;P&gt;i just saw interface g0/1 only from IDM.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 02:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432057#M856671</guid>
      <dc:creator>szekahungdanny</dc:creator>
      <dc:date>2010-06-03T02:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432058#M856673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would need to assign the traffic that you would like to direct towards 2 different virtual sensors via the policy-map configuration on the ASA, not via the AIP module configuration itself. You would need to configure the virtual sensor first on the AIP module, then you can choose which virtual sensors to send the traffic to via the ASA config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration guide for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i3.html#wp1877826"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i3.html#wp1877826&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 10:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432058#M856673</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-03T10:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432059#M856679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;EM&gt; &lt;/EM&gt;szekahungdanny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry, I didn't understand what exactly was confusing you. You don't need to create a new interface pair on the AIP-SSM for a second virtual sensor, the packets destined for a specific sensor will be tagged on the internal interface of the ASA. The syntax for your service policy would be:&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;STRONG class="cCN_CmdName"&gt;ips&lt;/STRONG&gt; &lt;SPAN class="cCp_CmdPlain"&gt;{&lt;/SPAN&gt;&lt;STRONG class="cKeyword"&gt;inline &lt;/STRONG&gt;&lt;SPAN class="cCp_CmdPlain"&gt;|&lt;/SPAN&gt; &lt;STRONG class="cKeyword"&gt;promiscuous&lt;/STRONG&gt;} {&lt;STRONG class="cKeyword"&gt;fail-close&lt;/STRONG&gt; | &lt;STRONG class="cKeyword"&gt;fail-open&lt;/STRONG&gt;} &lt;SPAN style="color: #0000ff;"&gt;[&lt;STRONG class="cBold"&gt;sensor&lt;/STRONG&gt; {&lt;EM class="cEmphasis"&gt;sensor_name&lt;/EM&gt; | &lt;EM class="cEmphasis"&gt;mapped_name&lt;/EM&gt;}]&lt;/SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;this allows traffic from different class-mapsto be sent to different virtual sensors (the mapped name is only relevant for multiple context, if the virtual sensor is mapped to a context-specific name).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But are you sure you want to have two virtual sensors just because of a different action of a single signature? That's not the design goal. The draw-back of two virtual sensors is, that you will have two class maps and you must duplicate every action on both traffic classes (like inspect etc) within your policy map.&lt;/P&gt;&lt;P&gt;Remember: a policy map is much like a switch/case/break construct of programming languages. Once a class matches only the actions of that class are executed, subsequent classes are ignored:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translated to "C" a policy map would be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot; Arial&amp;quot;: ; "&gt; &lt;SPAN style="color: blue; "&gt;switch&lt;/SPAN&gt;(traffic-class)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; {&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: blue; font-size: 10pt; "&gt;case&lt;/SPAN&gt; &lt;SPAN style="color: maroon; font-size: 10pt; "&gt;'match-criteria-class-1'&lt;/SPAN&gt;: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; {&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; policy-actions-for-class-1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS inline fail-closed sensor vs0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect something&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; QoS settings&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot; Arial&amp;quot;: ; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: blue; font-size: 10pt; "&gt;break&lt;/SPAN&gt;;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: blue; font-size: 10pt; "&gt;case&lt;/SPAN&gt; &lt;SPAN style="color: maroon; font-size: 10pt; "&gt;'match-criteria-class-2'&lt;/SPAN&gt;: &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; {&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; policy-actions-for-class-2;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPS inline fail-closed sensor vs1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect something&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; QoS settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot; Arial&amp;quot;: ; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: blue; font-size: 10pt; "&gt;break&lt;/SPAN&gt;;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; font-size: 10pt;"&gt; &lt;SPAN style="font-family: &amp;quot;Arial&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;Hope that helps understanding the issue, rather duplicate the signature in your existing sensor and edit traffic filters within the signature.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;Best regards,&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin-top: 0pt; margin-bottom: 0pt;"&gt;MiK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 11:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432059#M856679</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2010-06-03T11:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432060#M856683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ManyThanks to all...&lt;/P&gt;&lt;P&gt;i know using class-map into vs0, vs1...&lt;/P&gt;&lt;P&gt;but ..what i can't understand is .... when i create vs1, there're no interface could be selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in default "vs0", there're 1 interface gigaethernet 0/1.0 (blackplane)... how come no interface in vs1.&lt;/P&gt;&lt;P&gt;Now, I dump 2 pics . to explain what i difficult mean..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 16:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432060#M856683</guid>
      <dc:creator>szekahungdanny</dc:creator>
      <dc:date>2010-06-03T16:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432061#M856687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need 2 set of signature actions, not only a signature of action.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set A is using default signature&lt;/P&gt;&lt;P&gt;Set B is using custom signature which is no deny/drop actions, only Log actions&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 16:12:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432061#M856687</guid>
      <dc:creator>szekahungdanny</dc:creator>
      <dc:date>2010-06-03T16:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432062#M856690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;szekahungdanny wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ManyThanks to all...&lt;/P&gt;&lt;P&gt;i know using class-map into vs0, vs1...&lt;/P&gt;&lt;P&gt;but ..what i can't understand is .... when i create vs1, there're no interface could be selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in default "vs0", there're 1 interface gigaethernet 0/1.0 (blackplane)... how come no interface in vs1.&lt;/P&gt;&lt;P&gt;Now, I dump 2 pics . to explain what i difficult mean..&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;that should be perfectly OK, see:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_ssm.html#wpxref91337"&gt;http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_ssm.html#wpxref91337&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;H3 class="p_H_Head2" style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;AIP-SSM and Virtualization&lt;/SPAN&gt;&lt;/H3&gt;&lt;BR /&gt;&lt;P class="pB1_Body1" style="padding-left: 30px;"&gt;AIP-SSM has one interface, GigabitEthernet0/1. When you create multiple virtual sensors, you must assign this interface to only one virtual sensor. For the other virtual sensors you do not need to designate an interface.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;and further:&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;SPAN class="content"&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1" style="padding-left: 30px;"&gt;Follow this sequence to create virtual sensors on AIP-SSM &lt;SPAN style="color: #999999;"&gt;(and to assign them to adaptive security device contexts)&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="pB1_Body1" style="padding-left: 30px;"&gt;&lt;SPAN class="content"&gt;&lt;STRONG&gt;1. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Configure up to four virtual sensors on AIP-SSM.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1" style="padding-left: 30px;"&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;STRONG&gt;2. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Assign the AIP-SSM interface, GigabitEthernet0/1, to one of the virtual sensors.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;/P&gt;&lt;P class="pB1_Body1" style="padding-left: 30px;"&gt;&lt;STRONG style="color: #999999; "&gt;3. &lt;/STRONG&gt;&lt;SPAN style="color: #999999;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Assign virtual sensors to different contexts on the adaptive security device.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1" style="padding-left: 30px;"&gt;&lt;STRONG&gt;4. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Use MPF to direct traffic to the targeted virtual sensor.&lt;SPAN class="content"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;SPAN class="content"&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;I hope that helps how to handle multiple virtual sensors on the AIP-SSM&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;Still the question is why would you go through that trouble if you can duplicate the signature and change the action depending on the source/destination address configured in the siggnature details?&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;Keep it as simple as possible...&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;&lt;/P&gt;&lt;P class="pNN_NumNext"&gt;Rgds, MiKa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 23:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432062#M856690</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2010-06-03T23:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432063#M856692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you duplicate a signature you can define independent actions (log only, no drop or reset) for the duplicate that's the easiest solution. You don't need necessarily two virtual sensors for this simple task. Just create a second signature with the same definitions except for traffic filter (source and destination IP) and different actions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: I just thought of a third possibility: adjust threat rating and use event action filters. You can subtract the actions drop and reset for events which are rated "low" as defined by the event action rule. See (scroll down for SDM usage):&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a00808518b2.shtml"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a00808518b2.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: m.kafka, added event action filters&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jun 2010 23:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432063#M856692</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2010-06-03T23:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AIP with 2 virtual sensors?</title>
      <link>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432064#M856695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You do not need to assign the backplane interface to the new virtual sensor that you have just created. You just have to assign the interface to the default virtual sensor. It will by default send through the traffic from ASA through the backplane interface towards the AIP module. On the ASA, you can define which virtual sensor to send the traffic to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that clears the confusion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jun 2010 11:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aip-with-2-virtual-sensors/m-p/1432064#M856695</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-04T11:26:52Z</dc:date>
    </item>
  </channel>
</rss>

