54-6
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 54 Configuring the IPS Application on the AIP SSM and SSC
Configuring the AIP SSM/SSC
Step 2 (AIP SSM only) On the ASA 5500 in multiple context mode, specify which IPS virtual sensors are
available for each context (if you configured virtual sensors). See the “Assigning Virtual Sensors to a
Security Context (AIP SSM Only)” section on page 54-7.
Step 3 On the ASA 5500, identify traffic to divert to the AIP SSM/SSC. See the “Diverting Traffic to the AIP
SSM/SSC” section on page 54-8.
Configuring the Security Policy on the AIP SSM/SSC
This section describes how to access the IPS application in the AIP SSM/SSC.
Note See also the “Configuring the SSC Management Interface” section on page 53-4 to configure the SSC
management interface for ASDM access and other uses.
Detailed Steps
Step 1 To access IDM from ASDM, click Configuration > IPS.
Step 2 You are asked for the IP address or hostname of the AIP SSM/SSC.
• If the AIP SSM/SSC is running IPS Version 6.0 or later, ASDM retrieves IDM from the AIP
SSM/SSC and displays it as part of the ASDM interface. Enter the AIP SSM/SSC password and
click OK.
The IDM panes appear in the ASDM window.
• For the AIP SSM only, if it is running an earlier version of IPS software, ASDM displays a link to
IDM. Click the link to launch IDM in a new browser window. You need to provide a username and
password to access IDM.
If the password to access IDM is lost, you can reset the password using ASDM. See the “Password
Troubleshooting” section on page 53-6, for more information.
Step 3 Configure the IPS security policy.
For the AIP SSM only, if you configure virtual sensors in IPS Version 6.0 or above, you identify one of
the sensors as the default. If the ASA 5500 series adaptive adaptive security appliance does not specify
a virtual sensor name in its configuration, the default sensor is used.
Because the IPS software that runs on the AIP SSM/SSC is beyond the scope of this document, detailed
configuration information is available in the IPS documents at the following location:
http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/tsd_products_support_series_home.html
What to Do Next
• For the adaptive security appliance in multiple context mode, see the “Assigning Virtual Sensors to
a Security Context (AIP SSM Only)” section on page 54-7.
• For the adaptive security appliance in single context mode, see the “Diverting Traffic to the AIP
SSM/SSC” section on page 54-8.