Looking for an explanation of the gig0/0 interface in the AIP-SSM-20. The ASA runs 8.2 and the IPS runs 6.2.
The documentation I'm reading doesn't mention it all. I want a management interface separate from the default connection between the ASA and the ips module.
Please describe the issue in detail.
Here's a link that may help.
http://www.cisco.com/en/US/docs/security/ips/6.2/configuration/guide/cli/cli_initializing.html#wp1286695
Thanks for the reply.
This is for an AIP-SSM-20.
The Management interface for the module has what designation, gig0/0?
This IP address is different from the backplane default being used by the module to communicate with the ASA, correct?
The management interface is accesses via a physical port on the module itself, correct?
This same physical interface on the module is the reporting ip address being used when adding the sensor to MARS, correct?
GigabitEthernet0/0
Yes, the IP address is different. The physical port G0/0 is only used for management. The IP on the G0/0 of the module may be in the same subnet as the mangement interface of the ASA. Also you need to define a default gateway for the module. Whatever IP you configure for G0/0, would be used by MARS.
Hi Tanveer,
Thanks for the detailed response.
I believe that I was confusing the different modules.
Here is one last question from the setup command and the advanced configuration:
Management0/0 and gigabit 0/1 are given different IP addresses, correct? We want to use a same management vlan used by all networking devices. Does the gig0/1 have a different ip and is it the interface which connects to the ASA over the backplane?
Modify interface/virtual sensor configuration?[no]: yes
Current interface configuration
Command control: Management0/0
Unassigned:
Monitored:
GigabitEthernet0/1
Thank you in advance!
Hi Tanveer,
Thanks for the detailed response.
I believe that I was confusing the different modules.
Here is one last question from the setup command and the advanced configuration:
Management0/0 and gigabit 0/1 are given different IP addresses, correct? We want to use a same management vlan used by all networking devices. Does the gig0/1 have a different ip and is it the interface which connects to the ASA over the backplane?
Modify interface/virtual sensor configuration?[no]: yes
Current interface configuration
Command control: Management0/0
Unassigned:
Monitored:
GigabitEthernet0/1
Thank you in advance!
M0/0 is the only interface you would configure IP address on. That would be used for the management traffic.
You do not configure any IP on G0/0 or G0/1 as the traffic that is to be inspected flows from the ASA to the module internally. You just define the policy-map on ASA to identify the traffic that flows to the module for inspection.
Check this link for details:
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807335ca.shtml
This document was generated from the following thread: AIP-SSM Int gig0/0