Cisco 5510 Getting Started Guide - Page 184

About Deploying the Adaptive Security Appliance with the CSC SSM

Page 184 highlights

About Deploying the Adaptive Security Appliance with the CSC SSM Chapter 14 Configuring the CSC SSM content profiles it obtains from Trend Micro. It then forwards legitimate content on to the adaptive security appliance for routing, or blocks and reports content that is suspicious. In addition to obtaining content profiles from Trend Micro, system administrators can also customize the configuration so that the CSC SSM scans for additional traffic types or locations. For example, system administrators can configure the CSC SSM to block or filter specific URLs, as well as scan for FTP and e-mail parameters. You use ASDM for system setup and monitoring of the CSC SSM. For advanced configuration of content security policies in the CSC SSM software, you access the web-based GUI for the CSC SSM by clicking links within ASDM. This chapter describes how to configure the adaptive security appliance for the deployment. Use of the CSC SSM GUI is explained in the Cisco Content Security and Control SSM Administrator Guide. About Deploying the Adaptive Security Appliance with the CSC SSM In a network in which the adaptive security appliance is deployed with the CSC SSM, you configure the adaptive security appliance to send to the CSC SSM only the types of traffic that you want to be scanned. Figure 14-1 illustrates the basic traffic flow between a company network, the adaptive security appliance and CSC SSM, and the Internet. The network illustrated in Figure 14-1 includes the following: • An adaptive security appliance with a CSC SSM installed and configured • A service policy on the adaptive security appliance specifies which traffic is diverted to the CSC SSM for scanning 14-2 Cisco ASA 5500 Series Getting Started Guide 78-19186-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208

Chapter 14
Configuring the CSC SSM
About Deploying the Adaptive Security Appliance with the CSC SSM
14-2
Cisco ASA 5500 Series Getting Started Guide
78-19186-01
content profiles it obtains from Trend Micro. It then forwards legitimate content
on to the adaptive security appliance for routing, or blocks and reports content that
is suspicious.
In addition to obtaining content profiles from Trend Micro, system administrators
can also customize the configuration so that the CSC SSM scans for additional
traffic types or locations. For example, system administrators can configure the
CSC SSM to block or filter specific URLs, as well as scan for FTP and e-mail
parameters.
You use ASDM for system setup and monitoring of the CSC SSM. For advanced
configuration of content security policies in the CSC SSM software, you access
the web-based GUI for the CSC SSM by clicking links within ASDM.
This chapter describes how to configure the adaptive security appliance for the
deployment. Use of the CSC SSM GUI is explained in the
Cisco Content Security
and Control SSM Administrator Guide
.
About Deploying the Adaptive Security Appliance
with the CSC SSM
In a network in which the adaptive security appliance is deployed with the CSC
SSM, you configure the adaptive security appliance to send to the CSC SSM only
the types of traffic that you want to be scanned.
Figure 14-1
illustrates the basic traffic flow between a company network, the
adaptive security appliance and CSC SSM, and the Internet. The network
illustrated in
Figure 14-1
includes the following:
An adaptive security appliance with a CSC SSM installed and configured
A service policy on the adaptive security appliance specifies which traffic is
diverted to the CSC SSM for scanning