EasyManuals Logo

Cisco ASA 5506-X Configuration Guide

Cisco ASA 5506-X
428 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #105 background imageLoading...
Page #105 background image
6-23
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 6 ASA and Cisco TrustSec
Guidelines for Cisco TrustSec
Note If there is no matched IP-SGT mapping from the IP-SGT Manager, then a reserved SGT value of “0x0”
for “Unknown” is used.
The following table describes the expected behavior for egress traffic when configuring this feature.
The following table describes the expected behavior for to-the-box and from-the-box traffic when
configuring this feature.
Note If there is no matched IP-SGT mapping from the IP-SGT Manager, then a reserved SGT value of “0x0”
for “Unknown” is used.
The cts manual command and the
policy static sgt sgt_number command
are both issued.
SGT value is from the policy static sgt
sgt_number command.
SGT value is from the policy static sgt
sgt_number command.
The cts manual command and the
policy static sgt sgt_number trusted
command are both issued.
SGT value is from the inline SGT in the
packet.
SGT value is from the policy static sgt
sgt_number command.
Table 6-3 Ingress Traffic
Interface Configuration Tagged Packet Received Untagged Packet Received
Table 6-4 Egress Traffic
Interface Configuration Tagged or Untagged Packet Sent
No command is issued. Untagged
The cts manual command is issued. Tagged
The cts manual command and the propagate sgt command are both issued. Tagged
The cts manual command and the no propagate sgt command are both issued. Untagged
Table 6-5 To-the-box and From-the-box Traffic
Interface Configuration Tagged or Untagged Packet Received
No command is issued on the ingress interface for to-the-box
traffic.
Packet is dropped.
The cts manual command is issued on the ingress interface
for to-the-box traffic.
Packet is accepted, but there is no policy enforcement or SGT
propagation.
The cts manual command is not issued or the cts manual
command and no propagate sgt command are both issued on
the egress interface for from-the-box traffic.
Untagged packet is sent, but there is no policy enforcement.
The SGT number is from the IP-SGT Manager.
The cts manual command is issued or the cts manual
command and the propagate sgt command are both issued on
the egress interface for from-the-box traffic.
Tagged packet is sent. The SGT number is from the IP-SGT
Manager.

Table of Contents

Other manuals for Cisco ASA 5506-X

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA 5506-X and is the answer not in the manual?

Cisco ASA 5506-X Specifications

General IconGeneral
ModelASA 5506-X
Firewall Throughput750 Mbps
Maximum Firewall Connections50, 000
Maximum VPN Peers50
Integrated Ports8 x 1 GE
Stateful Inspection Throughput750 Mbps
Weight4.4 lb (2 kg)
Firewall Throughput (Multiprotocol)750 Mbps
Firewall Throughput (Application Visibility and Control AVC)250 Mbps
Concurrent Sessions50, 000
New Connections per Second10, 000
IPsec VPN Throughput100 Mbps
Interfaces8 x 1 GE
Memory4 GB
Flash Memory8 GB
Form FactorDesktop
VPN Throughput100 Mbps
Maximum Concurrent Sessions50, 000
New Sessions per Second10, 000
Operating Temperature32 to 104°F (0 to 40°C)
Storage Temperature-13 to 158°F (-25 to 70°C)
Power SupplyExternal
Humidity10% to 90% non-condensing

Related product manuals