<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM configuration assistance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676025#M87230</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the answers to your questions-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Does the ACL on AIP-SSM have any type of relations to the ASA ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans) No. ACL on SSM is completely independent of ACLs on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Our four interfaces are all in use. Is it possible to assign the SSM an IP address in the same subnet as the management interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans) Absolutely. You can assign the management port of SSM an IP in the same subnet as your managemnet interface. That way all management traffic will be kept independent of normal DATA traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Should then the management interface be used as the gateway for the SSM? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans) You are right .. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Mar 2007 20:10:28 GMT</pubDate>
    <dc:creator>vitripat</dc:creator>
    <dc:date>2007-03-16T20:10:28Z</dc:date>
    <item>
      <title>AIP-SSM configuration assistance</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676024#M87229</link>
      <description>&lt;P&gt;I have two questions regarding the AIP-SSM.&lt;/P&gt;&lt;P&gt;1) Does the ACL on AIP-SSM have any type of relations to the ASA ACL?&lt;/P&gt;&lt;P&gt;2) Our four interfaces are all in use. Is it possible to assign the SSM an IP address in the same subnet as the management interface?&lt;/P&gt;&lt;P&gt;3) Should then the management interface be used as the gateway for the SSM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 65.x.x.1 255.255.255.0 standby 65.x.x.2&lt;/P&gt;&lt;P&gt;!             &lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.x.1 255.255.255.0 standby 172.16.x.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.x.1 255.255.255.0 standby 192.168.x.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.x.1 255.255.255.0 standby 10.0.x.2 &lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:31:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676024#M87229</guid>
      <dc:creator>Tshi M</dc:creator>
      <dc:date>2019-03-10T10:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration assistance</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676025#M87230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the answers to your questions-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Does the ACL on AIP-SSM have any type of relations to the ASA ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans) No. ACL on SSM is completely independent of ACLs on ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Our four interfaces are all in use. Is it possible to assign the SSM an IP address in the same subnet as the management interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans) Absolutely. You can assign the management port of SSM an IP in the same subnet as your managemnet interface. That way all management traffic will be kept independent of normal DATA traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Should then the management interface be used as the gateway for the SSM? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ans) You are right .. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 20:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676025#M87230</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-16T20:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration assistance</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676026#M87231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;after making changes to the IDS sensor, it prompts for a node reboot. does this reboot affect the firewall as well (i.e. causing the firewall to reboot)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 13:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676026#M87231</guid>
      <dc:creator>Tshi M</dc:creator>
      <dc:date>2007-03-30T13:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration assistance</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676027#M87232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reboot required is just for the IPS on the SSM.  The ASA itself will not be rebooted, it is only the SSM module that will be rebooted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 16:45:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676027#M87232</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2007-03-30T16:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration assistance</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676028#M87233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If your ASA configuration is using the SSM module and it is configured as "fail-close", then only you will face issues when SSM module is reloaded. Make sure that ASA is configuration has following line if using SSM services-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ips {inline | promiscuous} fail-open&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way even if you reload the SSM module it wont break the traffic through ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 17:05:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676028#M87233</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-30T17:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM configuration assistance</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676029#M87234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not only that, but if your ASA's are in a failover configuration, if you reboot the SSM on the primary firewall, it will cause a failover to the standby.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2007 18:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-configuration-assistance/m-p/676029#M87234</guid>
      <dc:creator>jshelmer</dc:creator>
      <dc:date>2007-03-30T18:49:38Z</dc:date>
    </item>
  </channel>
</rss>

