Cisco IPS Module SSM-10 - how to configure in active/active failover
Posted on 2012-08-15
I have 2 ASA's that are setup in active/active failover. Each ASA has an ASA-SSM-10 IPS module.
I have 2 contexts - edge firewall (lets call it context1) and internal firewall (context2).
Context 1 is active on the 1st firewall and context2 is active on the second firewall.
I do not find any options or documentation on how the configuration would work exactly.
I want the IPS on the 1st ASA to monitor the context that is active on it (context1) and the IPS on the 2nd ASA to monitor context2.
Then when a device fails, the IPS on the remaining active device must monitor both contexts.
My problem is that it seems that the config of the 2 IPS's are not synched.
Please confirm if my following understanding is correct:
1. I will configure a virtual sensor on the 1st IPS. The context that is normally active on this ASA (context1) will then be linked to that virtual sensor.
2. I will then configure a another virtual sensor with a different name on the 2nd IPS. The conext that is normally active on that ASA (context2) will then be linked to that virtual sensor.
This should work, but what if one ASA fails? Will the context that now becomes active know that it must work with the available IPS?
If so, what must I do with the config?
Since the config of virtual sensors do not seem to sync, do I need to make the virtual sensor names and configs exactly the same on both devices? (i.o.w "sync" the config myself). If this is not done, then the virtual sensor that is not on the remaining active IPS will not be available to the context that had to failover.
Your assistance will be highly appreciated.