cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
539
Views
0
Helpful
1
Replies

5585-x with IPS SSM 40 module

parvezahmad90
Level 1
Level 1

Hello,

We have installed 5585-x in active/active mode with trasparent firewall.

We have created two virtual sersors for vs1 and vs2 in IPS module and linked with ASA context C1(vs1), C2(vs2) and admin(vs0).

As firewall is working in trasparent mode, we have bridge IP address for context C1 10.1.1.1 and for context C2 10.2.2.1.

I have added default routed for context C1 10.1.1.2 .It is in the outside of asa and SVI on switch.For the other context C2 10.2.2.2.

Kindlly advise IP address range for the IPS module and what should be the gateway for IPS module.AS the traffic is comming from outside and going to inside interface of ASA.

Please also let us know any use-case/best practices for this setup.

Regards,
Parvez           

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Parvez,

I am going to provide you a link that will demostrate what needs to be done depending on different scenarios

http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd5d03.shtml

http://www.cisco.com/en/US/products/sw/secursw/ps2113/products_tech_note09186a0080bd5d00.shtml

Enjoy and remember to rate all of the helpful posts, as important as a thanks

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card