18-8
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 18 ASA IPS Module
Configuring the ASA IPS module
If you do not have an inside router
If you have only one inside network, then you cannot also have a separate management network, which
would require an inside router to route between the networks. In this case, you can manage the ASA from
the inside interface instead of the Management 0/0 interface. Because the IPS module is a separate device
from the ASA, you can configure the IPS Management 1/0 address to be on the same network as the
inside interface.
ASA 5512-X through ASA 5555-X (Software Module)
These models run the IPS module as a software module, and the IPS management interface shares the
Management 0/0 interface with the ASA.
ASA Management 0/0
Internet
Management PC
Proxy or DNS Server (for example)
Router
ASA
IPS Management 1/0
Outside
IPS
Management
Inside
IPS Default
Gateway
ASA gateway for Management
334658
Internet
Layer 2
Switch
ASA
Inside
IPS Management 1/0
ASA Management 0/0 not used
Outside
IPS
IPS Default Gateway
Management PC
Proxy or DNS Server
(for example)
334660
ASA 5545-X
IPS Management 0/0
Default IP: 192.168.1.2
ASA Management 0/0
Default IP: 192.168.1.1
334665
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......