Cisco ASA 5515 - Configure IPS on another port

Dear Experts,

I have a question regarding a Cisco 5515 IPS configuration.
In the default setup the IPS is configured on management port 0/0.

I have two question.

- is it possible to configure this IPS on another port? like for example fastethernet 0/1 (nameif = inside)?
- and is it possible to manage the IPS from outside? on the external IP Adres?

How can i configure this? can you give me an example? CLI commands or gui?

Thanks in advance.

Robin
jav_sevenofnineIT ConsultantAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Salah Eddine ELMRABETTechnical Lead Manager (Owner)Commented:
Hi Robin,

To manage your ASA from outside, you have two choice:

Enable management on the outside interface using ASDM (GUI using HTTP) and SSH
Configure a remote access VPN and manage the ASA as you did from Inside

You have to note that only one management interface can be chosen.

There is another question in EE talking about remotely manage ASA, witch you can access here: http://www.experts-exchange.com/Hardware/Networking_Hardware/Firewalls/Q_27410836.html

For IPS configuration, please refer to the following:

Cisco ASA IPS Module Quick Start Guide  

Configuring the ASA 5500-X IPS SSP

Configuring the IPS Module:

Best Regards.

Salah
jav_sevenofnineIT ConsultantAuthor Commented:
Dear Salah,

thanks for your comment.
Accessing the ASA from outside isn't the problem.
When i open the asa with ASDM. and click on the IPS button on the left side. it cant connect. because it's only accessible from the management interface on the same subnet.
I want to manage the IPS when i am on the inside network but also on the outside interface :)

Thanks for you help so far.

Any suggestions?

Kind Regards.

Robin
Salah Eddine ELMRABETTechnical Lead Manager (Owner)Commented:
Hi Robin

So in this case you have to configure VPN using IP pool from the same IPS management interface subnet, then when you want to manage the IPS remotely you will establish the VPN connection and you computer will act as management interface network member, then you can manage the ASA using the Internal management IP.

Best Regards.

Salah

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jav_sevenofnineIT ConsultantAuthor Commented:
Thanks!
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.