cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1413
Views
15
Helpful
6
Replies

Cisco WSA and SMA ports

Asfandyar70754
Level 1
Level 1

Hey Experts,

 

Looking for some clarity on ports of Cisco WSA S395-K9 and SMA M395-K9.

So have implemented Web Security on VMs couple of times but never had chance to implement it physically. So I had read in documents and in my previous VM deployments about Proxy and Traffic monitoring ports but I did saw the WSA and SMA physically and could not see these ports, instead I saw Data 1 and Data 2 port.

I have attached a rough diagram of my network/deployment and a snap of SMA and WSA ports.

Can you guys please take a look into this and let me know that where the traffic monitoring and proxy ports are? Are Data 1 and 2 actually these proxy and monitoring ports?

And secondly do I need to physically connect the SMA with WSA ?

Thanks

6 Replies 6

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @Asfandyar70754,

You can find port details in HW installation guide for S395, and M395.

And no, there is no requirement to physically connect them together. You just need to have IP connectivity between these devices.

BR,

Milos

https://www.cisco.com/c/en/us/td/docs/security/content_security/x95_series/hw/guide/wsa/install-wsa-x95/overview.html#id_84804
Look at figure 10
The port marked 3 is for management. 11/12 are the proxy ports (P1/P2), and 13/14 are the "traffic monitoring" ports (T1/T2)
You don't have to physically connect them, just IP between the SMA Management port and the WSA Management port

Hi Ken,

 

Thanks a lot.

What about Data 1-5 ports of SMA M395, what are they used for ?

Screenshot attached.

Nothing.
The SMA box is a standard UCS box off the manufacturing line... so physically its set up with a 4 port card.

Hi Ken,

Sorry I didn't get it, I will have to connect it to switch, so what port do I use, I suppose these Data ports right?

and secondly can I use 2 Data ports for redundancy?

I just use the Management interface.

You can use the others to split up traffic, say one for management traffic and put the spam quarantine access on the other.

 

As of 14.1 they still don't do etherchannel or similar interface load balancing/failover.