Solved

ASA 5510 CSC-SSM 10 Module

Posted on 2014-11-05
4
40 Views
Last Modified: 2016-07-17
i have one cisco ASA 5510 firewall with CSC-SSM 10 Module, which i use for filtering, its working good, i am sending all the the traffic to CSC-SSM module for scanning,  i do not want to send some destination traffic to CSC-SSM 10 module for scanning, those destinations are two ip addresses, if traffic is going to these two ip addresses, i do not want ASA to send that traffic to CSC-SSM module.
0
Comment
Question by:Ajeet Kumar
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
Ken Boone earned 500 total points
ID: 40424089
So in your config you should have something like this:

access-list IPS permit ip any any

class-map my_ips_class
 match access-list IPS
 class-map all_traffic
  match access-list all_traffic
 class-map inspection_default
  match default-inspection-traffic
 !
 !
 policy-map my-ids-policy
  class my-ips-class
   ips promiscuous fail-close
 !
 service-policy my-ids-policy global


BTW.. this sample was taken from : http://www.cisco.com/c/en/us/td/docs/security/ips/6-0/configuration/guide/cli/cliguide/cliSSM.html#wp1030972

So what you need to do is change your IPS access-list.
Instead of  just this:

access-list IPS permit ip any any

do this
access-list IPS deny ip any host x.x.x.x
access-list IPS deny ip host x.x.xx any
access-list IPS deny ip any host y.y.y.y
access-list IPS deny ip host y.y.y.y any
access-list IPS permit ip any any

x.x.x.x and y.y.y.y are the two destination or sources you do not want to scan.  Make sure the ACL is in that order with the permit ip any any at the bottom.
0
 
LVL 24

Expert Comment

by:Ken Boone
ID: 41714584
I provided a valid solution in my comments.  I gave an example with detailed instructions.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question