17-6
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 17 ASA CX Module
Licensing Requirements for the ASA CX Module
Licensing Requirements for the ASA CX Module
The ASA CX module and PRSM require additional licenses, which need to be installed in the module
itself rather than in the context of the ASA. The ASA itself requires no additional licenses. See the ASA
CX documentation for more information.
Prerequisites for ASA CX
To use PRSM to configure the ASA, you need to install a certificate on the ASA for secure
communications. By default, the ASA generates a self-signed certificate. However, this certificate can
cause browser prompts asking you to verify the certificate because the publisher is unknown. To avoid
these browser prompts, you can instead install a certificate from a known certificate authority (CA). If
you request a certificate from a CA, be sure the certificate type is both a server authentication certificate
and a client authentication certificate. See the general operations configuration guide for more
information.
Guidelines for ASA CX
Context Mode Guidelines
Starting with ASA CX 9.1(3), multiple context mode is supported.
However, the ASA CX module itself (configured in PRSM) is a single context mode device; the
context-specific traffic coming from the ASA is checked against the common ASA CX policy. Therefore,
you cannot use the same IP addresses in multiple contexts; each context must include unique networks.
Firewall Mode Guidelines
Supported in routed and transparent firewall mode. Traffic-forwarding interfaces are only supported in
transparent mode.
Failover Guidelines
Does not support failover directly; when the ASA fails over, any existing ASA CX flows are transferred
to the new ASA, but the traffic is allowed through the ASA without being inspected by the ASA CX.
Only new flows received by the new ASA are acted upon by the ASA CX module.
ASA Clustering Guidelines
Does not support clustering.
IPv6 Guidelines
•
Supports IPv6.
•
(9.1(1) and earlier) Does not support NAT 64. In 9.1(2) and later, NAT 64 is supported.
Model Guidelines
•
Supported only on the ASA 5585-X and 5512-X through ASA 5555-X. See the
Cisco ASA
Compatibility Matrix
for more information:
http://www.cisco.com/en/US/docs/security/asa/compatibility/asamatrx.html
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......