取消
显示结果 
搜索替代 
您的意思是: 
cancel
4362
查看次数
12
有帮助
3
回复

ASA 5525X的IPS模块配置为监控模式,接交换机SPAN目的口,IPS接收不到数据流

huangfei05201
Level 1
Level 1
ASA5525X防火墙做旁路IPS使用,两台交换机各有一个SPAN将流量送到5525X的两个接口,我配好了登录IPS可以看到接口有接收到流量,但IPS却没有一个事件,不知道哪里配置有问题呢,下面是相关配置:
==============ASA===========
!
firewall transparent

interface GigabitEthernet0/0
nameif inside_A
security-level 100
!
interface GigabitEthernet0/1
nameif inside_B
security-level 100
!
!
interface Management0/0
management-only
nameif management
security-level 100
ip address 192.168.1.10 255.255.255.0
!
access-list IPS extended permit ip any any
access-group IPS global
route management 0.0.0.0 0.0.0.0 192.168.1.254
!
class-map IPS_Class
match access-list IPS
!
policy-map global_policy
class IPS_Class
ips promiscuous fail-open
!
service-policy global_policy global
==============IPS模块===========
service analysis-engine
virtual-sensor vs0
physical-interface PortChannel0/0
exit
exit
IPS功能已经打开:
Licensed features for this platform:
Maximum Physical Interfaces : Unlimited perpetual
Maximum VLANs : 200 perpetual
Inside Hosts : Unlimited perpetual
Failover : Active/Active perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
Security Contexts : 2 perpetual
GTP/GPRS : Disabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 750 perpetual
Total VPN Peers : 750 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
IPS Module : Enabled perpetual
Cluster : Disabled perpetual
3 条回复3

Yanli Sun
Community Manager
Community Manager
感谢您的提问,会有小伙伴为您解答的!:):handshake

pebao
Cisco Employee
Cisco Employee

yanzha4
Spotlight
Spotlight
pebao 发表于 2016-6-16 10:12 back.gif
请按照下面的链接检查你的配置:
http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/ips/ip ...

很好的文档
入门指南

使用上面的搜索栏输入关键字、短语或问题,搜索问题的答案。

我们希望您在这里的旅程尽可能顺利,因此这里有一些链接可以帮助您快速熟悉思科社区:









快捷链接