Download Print this page

Cisco ASA 5506-X Configuration Manual page 377

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Chapter 17
ASA CX Module
For the 5512-X through ASA 5555-X, you must install a Cisco solid state drive (SSD). For more
information, see the ASA 5500-X hardware guide.
Monitor-Only Mode Guidelines
Monitor-only mode is strictly for demonstration purposes and is not a normal operational mode for the
module.
You cannot configure both monitor-only mode and normal inline mode at the same time on the ASA.
Only one type of security policy is allowed. In multiple context mode, you cannot configure
monitor-only mode for some contexts, and regular inline mode for others.
The following features are not supported in monitor-only mode:
The ASA CX does not perform packet buffering in monitor-only mode, and events will be generated
on a best-effort basis. For example, some events, such as ones with long URLs spanning packet
boundaries, may be impacted by the lack of buffering.
Be sure to configure both the ASA policy and the ASA CX to have matching modes: both in
monitor-only mode, or both in normal inline mode.
Additional guidelines for traffic-forwarding interfaces:
The ASA must be in transparent mode.
You can configure up to 4 interfaces as traffic-forwarding interfaces. Other ASA interfaces can be
used as normal.
Traffic-forwarding interfaces must be physical interfaces, not VLANs or BVIs. The physical
interface also cannot have any VLANs associated with it.
Traffic-forwarding interfaces cannot be used for ASA traffic; you cannot name them or configure
them for ASA features, including failover or management-only.
You cannot configure both a traffic-forwarding interface and a service policy for ASA CX traffic.
Additional Guidelines and Limitations
See
You cannot change the software type installed on the hardware module; if you purchase an ASA CX
module, you cannot later install other software on it.
Deny policies
Active authentication
Decryption policies
Compatibility with ASA Features, page
17-5.
Cisco ASA Series Firewall CLI Configuration Guide
Guidelines for ASA CX
17-7

Hide quick links:

Advertisement

loading