EasyManuals Logo

Cisco ASA 5515-X Cli Configuration Guide

Cisco ASA 5515-X
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #1451 background imageLoading...
Page #1451 background image
1-3
Cisco ASA Series CLI Configuration Guide
Chapter 1 Using Protection Tools
Configuring IP Audit for Basic IPS Support
Configuring IP Audit for Basic IPS Support
The IP audit feature provides basic IPS support for the ASA that does not have an AIP SSM. It supports
a basic list of signatures, and you can configure the ASA to perform one or more actions on traffic that
matches a signature.
This section includes the following topics:
• Configuring IP Audit, page 1-3
• IP Audit Signature List, page 1-4
Configuring IP Audit
To enable IP audit, perform the following steps:
Step 1 To define an IP audit policy for informational signatures, enter the following command:
hostname(config)# ip audit name name info [action [alarm] [drop] [reset]]
Where alarm generates a system message showing that a packet matched a signature, drop drops the
packet, and reset drops the packet and closes the connection. If you do not define an action, then the
default action is to generate an alarm.
Step 2 To define an IP audit policy for attack signatures, enter the following command:
hostname(config)# ip audit name name attack [action [alarm] [drop] [reset]]
Where alarm generates a system message showing that a packet matched a signature, drop drops the
packet, and reset drops the packet and closes the connection. If you do not define an action, then the
default action is to generate an alarm.
Step 3 To assign the policy to an interface, enter the following command:
ip audit interface interface_name policy_name
Step 4 To disable signatures, or for more information about signatures, see the ip audit signature command in
the command reference.
•

Table of Contents

Other manuals for Cisco ASA 5515-X

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA 5515-X and is the answer not in the manual?

Cisco ASA 5515-X Specifications

General IconGeneral
Firewall Throughput1.2 Gbps
Maximum Concurrent Sessions250, 000
VPN Throughput200 Mbps
Maximum VPN Peers250
Interfaces6 x Gigabit Ethernet
IPsec VPN Throughput200 Mbps
Memory4 GB
Flash Memory4 GB
Form Factor1RU
IPS Throughput250 Mbps
Concurrent Sessions250, 000
Security Contexts2
Power SupplyAC power supply (100-240V)

Related product manuals