Cisco 5510 Getting Started Guide - Page 177

Diverting Traffic to the AIP SSM

Page 177 highlights

Chapter 13 Configuring the AIP SSM Configuring the AIP SSM hostname(config-ctx)# allocate-interface gigabitethernet0/0.110-gigabitethernet0/0.115 int3-int8 hostname(config-ctx)# allocate-ips sensor1 ips1 default hostname(config-ctx)# allocate-ips sensor2 ips2 hostname(config-ctx)# config-url ftp://user1:[email protected]/configlets/test.cfg hostname(config-ctx)# member gold hostname(config-ctx)# context sample hostname(config-ctx)# allocate-interface gigabitethernet0/1.200 int1 hostname(config-ctx)# allocate-interface gigabitethernet0/1.212 int2 hostname(config-ctx)# allocate-interface gigabitethernet0/1.230-gigabitethernet0/1.235 int3-int8 hostname(config-ctx)# allocate-ips sensor1 ips1 hostname(config-ctx)# allocate-ips sensor3 ips2 hostname(config-ctx)# config-url ftp://user1:[email protected]/configlets/sample.cfg hostname(config-ctx)# member silver hostname(config-ctx)# changeto context A ... Diverting Traffic to the AIP SSM To identify traffic to divert from the adaptive adaptive security appliance to the AIP SSM, perform the following steps. In multiple context mode, perform these steps in each context execution space. Step 1 To identify the traffic that you want to be inspected by the AIP SSM, add one or more class maps using the class-map command. For example, you can match all traffic using the following commands: hostname(config)# class-map IPS hostname(config-cmap)# match any To match specific traffic, you can match an access list: hostname(config)# access list IPS extended permit ip any 10.1.1.1 255.255.255.255 hostname(config)# class-map IPS hostname(config-cmap)# match access-list IPS 78-19186-01 Cisco ASA 5500 Series Getting Started Guide 13-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208

13-11
Cisco ASA 5500 Series Getting Started Guide
78-19186-01
Chapter 13
Configuring the AIP SSM
Configuring the AIP SSM
hostname(config-ctx)#
allocate-interface
gigabitethernet0/0.110-gigabitethernet0/0.115 int3-int8
hostname(config-ctx)#
allocate-ips sensor1 ips1 default
hostname(config-ctx)#
allocate-ips sensor2 ips2
hostname(config-ctx)#
config-url
ftp://user1:[email protected]/configlets/test.cfg
hostname(config-ctx)#
member gold
hostname(config-ctx)#
context
sample
hostname(config-ctx)#
allocate-interface gigabitethernet0/1.200 int1
hostname(config-ctx)#
allocate-interface gigabitethernet0/1.212 int2
hostname(config-ctx)#
allocate-interface
gigabitethernet0/1.230-gigabitethernet0/1.235 int3-int8
hostname(config-ctx)#
allocate-ips sensor1 ips1
hostname(config-ctx)#
allocate-ips sensor3 ips2
hostname(config-ctx)#
config-url
ftp://user1:[email protected]/configlets/sample.cfg
hostname(config-ctx)#
member silver
hostname(config-ctx)#
changeto context A
...
Diverting Traffic to the AIP SSM
To identify traffic to divert from the adaptive adaptive security appliance to the
AIP SSM, perform the following steps. In multiple context mode, perform these
steps in each context execution space.
Step 1
To identify the traffic that you want to be inspected by the AIP SSM, add one or
more class maps using the
class-map
command.
For example, you can match all traffic using the following commands:
hostname(config)#
class-map IPS
hostname(config-cmap)#
match any
To match specific traffic, you can match an access list:
hostname(config)#
access list IPS extended
permit ip any 10.1.1.1
255.255.255.255
hostname(config)#
class-map IPS
hostname(config-cmap)#
match access-list IPS