Cisco IPS4345 Manual de usuario Pagina 10

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 61
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 9
Cisco Intrusion Prevention System Security Target
1.2.2.2 Cisco IPS SSP Hardware Modules
The IPS SSP hardware modules install to ASA 5500-X series firewalls. The host ASA provides
power and cooling for the hardware module, but the hardware module provides its own physical
management port. The IPS hardware module runs its own IPS operating system independent of
the ASA operating system, with its own set of administrative users, its own audit configurations,
etc. Administrators of the ASA cannot authenticate to the IPS and thus cannot modify the
configuration of the IPS.
1.2.2.3 Cisco IPS SSP Software Modules
The IPS SSP software modules function just like the IPS hardware modules except they rely on
the host ASA to provide physical interfaces for local and remote administration of the IPS. The
IPS SSP software module and the ASA share the network-based Management interface (used for
remote access, and audit log transmission); however, the IPS SSP and ASA each has its own
separate MAC addresses and IP addresses. The IPS administrator configures the IP address of
the IPS management interface within the IPS operating system, though physical characteristics
(such as enabling the interface) on performed in the ASA operating system by the ASA
administrator. The IPS SSP software modules can be installed to ASA in any of the ASA 5500-
X models.
1.2.2.4 Cisco IPS Device Manager (IDM)
Cisco IDM is a Web-based tool/applet for sensor configuration and management. It can be
accessed through Internet Explorer, Netscape, or Mozilla, by using the browser to connect to the
IPS management interface, and when downloaded initiates its own Transport Layer Security
(TLS) connection to the IPS for remote administration.
1.2.3 Non-TOE Components
1.2.3.1 Cisco ASA 5585-X
The Cisco ASA 5585-X is a high-performance, 2-slot chassis, with the firewall/VPN Security
Services Processor (SSP) occupying the bottom slot, and the IPS Security Services Processor
(IPS SSP) in the top slot of the chassis. The firewall/VPN SSP is required to run IPS on the
Cisco ASA 5585-X. The IPS software runs on the IPS SSP hardware module. The Cisco ASA
5585-X Security Appliances scale from the Cisco Borderless Network Architecture to data center
architectures, with integrated form factors ranging from 4 Gbps to 40 Gbps.
Vista de pagina 9
1 2 ... 5 6 7 8 9 10 11 12 13 14 15 ... 60 61

Comentarios a estos manuales

Sin comentarios