Download Print this page

Cisco ASA 5506-X Configuration Manual page 403

Cli
Hide thumbs Also See for ASA 5506-X:

Advertisement

Chapter 18
ASA IPS Module
Licensing Requirements for the ASA IPS module
The following table shows the licensing requirements for this feature:
Model
License Requirement
ASA 5512-X,
IPS Module License.
ASA 5515-X,
Note
ASA 5525-X,
ASA 5545-X,
ASA 5555-X
ASA 5585-X
Base License.
All other models
No support.
Guidelines and Limitations
This section includes the guidelines and limitations for this feature.
Model Support
Additional Guidelines
ASA 5512-X, ASA 5515-X, ASA 5525-X, ASA 5545-X, ASA 5555-X—These models run the
ASA IPS module as a software module. The IPS management interface shares the
Management 0/0 interface with the ASA. Separate MAC addresses and IP addresses are
supported for the ASA and ASA IPS module. You must perform configuration of the IPS
IP address within the IPS operating system (using the CLI or ASDM). However, physical
characteristics (such as enabling the interface) are configured on the ASA. You can remove the
ASA interface configuration (specifically the interface name) to dedicate this interface as an
IPS-only interface. This interface is management-only.
The IPS module license lets you run the IPS software module on the ASA. You must also
purchase a separate IPS signature subscription; for failover, purchase a subscription for each
unit. To obtain IPS signature support, you must purchase the ASA with IPS pre-installed (the
part number must include "IPS"). The combined failover cluster license does not let you pair
non-IPS and IPS units. For example, if you buy the IPS version of the ASA 5515-X (part
number ASA5515-IPS-K9) and try to make a failover pair with a non-IPS version (part
number ASA5515-K9), then you will not be able to obtain IPS signature updates for the
ASA5515-K9 unit, even though it has an IPS module license inherited from the other unit.
See the Cisco ASA Compatibility Matrix for information about which models support which
modules:
http://www.cisco.com/en/US/docs/security/asa/compatibility/asamatrx.html
ASDM 7.3(2) and later is not compatible with IPS 7.3(2) or earlier. To manage IPS, connect to its
IP address directly in your browser.
The total throughput for the ASA plus the IPS module is lower than ASA throughput alone.
ASA 5512-X through ASA 5555-X—See
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-700608.
html
Licensing Requirements for the ASA IPS module
Cisco ASA Series Firewall CLI Configuration Guide
18-5

Hide quick links:

Advertisement

loading