Solved

redundant ASA or PIX configuration

Posted on 2013-06-04
4
462 Views
Last Modified: 2013-11-29
For years I have used Sonicwall and set it up for redundant / failover.  I just set up a heartbeat cable between the two identical model Sonicwall devices, and if one dies, the other comes online with the exact same LAN and Inet IP addresses.

Is there a very, very simple document or tutorial to walk me through doing this exact same thing with two PIX or two ASA devices?

Oh, one other sidebar question.  do ASA devices also act as Intrusion Detection devices?  Or is that a different Cisco product?

thank  you,
Jeff
0
Comment
Question by:jgrammer42
  • 2
  • 2
4 Comments
 
LVL 28

Expert Comment

by:asavener
Comment Utility
Active/Standby configuration:  http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml

There is basic IPS built into the ASA product.  There is a more full-featured IPS module that you can install and configure as well.
0
 

Author Comment

by:jgrammer42
Comment Utility
asavener,
Yes, I have seen that link.  I was looking for something a little more "step by step".  but if that is all there is, I guess I can go with that.

What "basic IPS" functions are in the ASA.   And what more full-featured functions are added by that module?  (I am assuming this is a hardware add in module, correct?)

thank you,
Jeff
0
 
LVL 28

Accepted Solution

by:
asavener earned 500 total points
Comment Utility
See these pages for info on what the ASA can do out of the box:

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/protect.html

http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/inspect.html


The IPS module is a hardware add on.  It has the ability to perform advanced IPS functions, download updated patters/definitions, learn normal traffic patterns and alert when anomalies are detected, etc.

IPS module quick guide:  http://www.cisco.com/en/US/docs/security/asa/quick_start/ips/ips_qsg.html

IPS module overview:  http://www.cisco.com/en/US/prod/collateral/routers/ps5853/ps5875/prod_presentation0900aecd806ccf26.pdf
0
 

Author Closing Comment

by:jgrammer42
Comment Utility
Thank you very much!
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now