cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2457
Views
0
Helpful
5
Replies

ASDM Cant connect to IPS

agent2007
Level 1
Level 1

Hello

I have configured an SSC-5 card in an asa 5505 and everything is working perfectly.  One of the things you need to do when configuring is configure allow-ssc-mgmt on the physical int on the asa to allow it manage the AIP card via that network card.  Is the same approach used on the AIP SSM modules in the bigger asa's as I cant communicate with the module via asdm.  Am I missing something obvious?

Tks

5 Replies 5

rhermes
Level 7
Level 7

What entries do you have in your Allowed Hosts list on the sensor?

haivrajesh
Level 1
Level 1

You can Manage thru ASDM can you give me a clear idea what you are trying to do?

hi guys tks for the replies.

the sensor is on another site so I dont have direct access to it but basically if I connect to the asa via the asdm (on the external ip of the asa) and then from within that session if I click on IPS, it wont connect.  on the acl on the IPS should I have the IP that I connect to the asa from on it?  i.e my public IP?  if you can explain to me exactly what happens when you click on the IPS part of asdm?  It just establishes a connection to port 443 on the IPS sensor right?

tks

First You check

# Sh module

The module is detected the sense.then you can change the ip settings and you can access the IPs directly from ASDM with ips ip.

No need to acces asa(asdm) and access the ips.Let explain indepth if you are still have problem.

Rajeswar.

Hi,

I have suggested with other post also same.(same solution is for other post also)

Management IP address :192.168.1.2/24

Management Hosts:192.168.1.0/24

Gateway:192.168.1.1

For Changine the AIP ssc-5 settins Follow the Steps

Login ASA

asa# configure terminal

asa (config)# interface vlan 1
asa (config-if)# no allow-ssc-mgmt
asa(config)# interface vlan 20
asa (config-if)# allow-ssc-mgmt
asa# hw-module module 1 ip 209.165.200.255 255.255.255.224 209.165.200.245

After this you can access the ips directly from asdm .

Review Cisco Networking for a $25 gift card