Manuel d'utilisation / d'entretien du produit ASA 5500 du fabricant Cisco Systems
Aller à la page of 144
Corporate Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 526-4100 C i s c o ASA 5 5 0 0 Se r i e.
THE SPECIFICA TIONS AND IN FORMA TION REGARDING THE PRODUCTS IN THIS MAN U AL ARE SUBJECT TO CHANGE WITHOUT NO TICE. ALL ST A TEMENTS, INFORMA TION, AND RECOMMEND A TION S IN THIS MANU AL ARE BELIEVED TO BE A CCURA TE BUT ARE PRESENTED WITHOUT W ARRANTY OF ANY KIN D, EXPRESS OR IMPLIED .
iii Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 CONTENTS CHAPTER 1 Before You Begin 1-1 ASA 5500 1-1 ASA 5500 with AIP SSM 1-2 ASA 5500 with CSC SSM 1-3 ASA 55.
Contents iv Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 CHAPTER 4 Connecting Interfa ce Cables 4-1 Connecting Cable s to Interfaces 4-2 What to Do Nex t 4-10 CH.
v Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Contents Starting ASDM 7-4 Configuring the FWSM for an IPsec Remote-Access VPN 7-5 Selecting VP N Client Types 7-.
Contents vi Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 CHAPTER 9 Configuring the AIP SSM 9-1 AIP SSM Configuration 9-1 Overview of Configuration Process 9-2 Co.
CH A P T E R 1-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 1 Before You Begin Use the follo wing table to f ind the instal lation and configuration steps that are required for your impl ementation of the adapti ve security appliance.
Chapter 1 Be fore You Begin ASA 5500 with AIP SSM 1-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 ASA 5500 with AIP SSM Conf igure the adapti ve security ap pli.
1-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 1 Before You Begin ASA 5500 with CSC SSM ASA 5500 with CSC SSM Configure IPS soft ware for intrusion pr.
Chapter 1 Be fore You Begin ASA 5500 with 4GE SSM 1-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 ASA 5500 with 4GE SSM Conf igure the CSC SSM Ci sco Content Se.
CH A P T E R 2-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 2 Installing the Cisco ASA 5500 War ni ng Only trained and qualified pe rsonnel should be allowed to in stall, replace, or service this equipment.
Chapter 2 Installing the Cisco ASA 5500 Verifying the Package Contents 2-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Verifying the Package Contents V erify th.
2-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 2 Installing the Cisco ASA 5500 Installing the Chassis Installing the Chassis This section descri bes how to rack-mou nt and install the adapti ve security appliance.
Chapter 2 Installing the Cisco ASA 5500 Installing the Chassis 2-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Rack-Mounting the Chassis T o rack-mount the chassis, perform the following steps: Step 1 Attach the rack-mount brackets to the ch assis using the supplied screws.
2-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs Figur e 2-3 Rack-Mounting the Chassis T o remov e the chassis from the rack, remove the screws that a ttach the chassis to the rack, and then remov e the chassis.
Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs 2-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figur e 2-4 F ront P anel LEDs LED Color State Description 1 Power Green On The system has po wer . 2 Status Green Flashing The po wer-up d iagnostics are running or the system is bo oting.
2-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs Figure 2-5 sho ws the rear panel features fo r the adapti ve security appliance.
Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs 2-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figure 2-6 sho ws the adaptive security appliance rear panel LEDs. Figur e 2-6 Rear Pa nel Link and Speed Indicator LEDs Ta b l e 2 - 1 lists the rear MGMT and Network interface LEDs.
2-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 2 Installing the Cisco ASA 5500 What to Do Next What to Do Next Continue w ith one of the f ollowing chapters: T o Do This .
Chapter 2 Installing the Cisco ASA 5500 What to D o Next 2-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01.
CH A P T E R 3-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 3 Installing Optional SSMs This chapter pro vides information about installing optional SSMs (Secu rity Services Modules) and their com ponents.
Chapter 3 Installing Optional SSMs Cisco 4GE SSM 3-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 4GE SSM Components Figure 3-1 lists the Cisco 4GE SSM ports and LEDs. Figur e 3-1 Cisco 4GE SSM P orts and LEDs Note Figure 3-1 sho ws SFP modules installed in the port slots.
3-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 3 Installing Opti onal SSMs Cisco 4GE SSM Installing the Ci sc o 4 GE S SM T o install a new C isc o 4 GE S SM for the f irst time, perform the foll owing steps: Step 1 Po wer of f the adapti ve security appliance.
Chapter 3 Installing Optional SSMs Cisco 4GE SSM 3-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 4 Insert the C isc o 4 GE S SM through the slot openin g as shown i n Figure 3-3 .
3-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 3 Installing Opti onal SSMs Cisco 4GE SSM SFP Module The adapti ve securi ty appliance uses a field-replaceable SFP module to establish Gigabit connect ions.
Chapter 3 Installing Optional SSMs Cisco 4GE SSM 3-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Use only Cisco-certif ied SFP modules on th e adapti ve security appliance. Each SFP module has an internal serial EEP R OM that is encode d with security information.
3-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 3 Installing Opti onal SSMs Cisco 4GE SSM Figure 3-4 Installing an SFP Module Caution Do not remov e the optical port plugs fro m the SFP until you are ready t o connect the cables .
Chapter 3 Installing Optional SSMs Cisco AIP SSM and CSC SSM 3-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Cisco AIP SSM and CSC SSM The ASA 5500 series adapt.
3-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 3 Installing Opti onal SSMs Cisco AIP SSM and CSC SSM Figur e 3-5 SSM LEDs Ta b l e 3 - 5 describes the SSM LEDs. Installing an SSM T o install a ne w SSM, perform the follo wing steps: Step 1 Po wer of f the adapti ve security appliance.
Chapter 3 Installing Optional SSMs What to D o Next 3-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figur e 3-6 Removing the Scr ews from the Slot Co ver Step 4 Insert the SSM into the slot opening as sho wn in Figure 3-7 .
CH A P T E R 4-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 4 Connecting Interface Cables This chapter d escribes ho w to connect the cables to the Console, Auxiliary , Management, Cisco 4GE SSM , and SSM ports .
Chapter 4 Conn ecting Interface Cables Connecting Cab l es to Interfaces 4-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Connecting Cables to Interfaces T o con.
4-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 4 Connecting Interface Cables Connecting Cables to Interfaces Figur e 4-1 Connecting t o the Management.
Chapter 4 Conn ecting Interface Cables Connecting Cab l es to Interfaces 4-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 b.
4-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 4 Connecting Interface Cables Connecting Cables to Interfaces c.
Chapter 4 Conn ecting Interface Cables Connecting Cab l es to Interfaces 4-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 d. Cisco 4GE SSM • Ethernet port – Connect one RJ-45 connecto r to the Ethernet port of the Cisco 4GE SSM as sho wn in Figure 4-4 .
4-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 4 Connecting Interface Cables Connecting Cables to Interfaces • SFP modules – Insert and slide the SFP module into the SFP port until you hear a click.
Chapter 4 Conn ecting Interface Cables Connecting Cab l es to Interfaces 4-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figur e 4-6 Connecting the LC Connector – Connect the other end to your networ k de vices, suc h as routers, switches, or hubs.
4-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 4 Connecting Interface Cables Connecting Cables to Interfaces Figure 4-7 Connecting to the M an a gem e.
Chapter 4 Conn ecting Interface Cables What to D o Next 4-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 f. Ethernet port s – Connect the RJ-4 5 connector to the Et hernet port as sho wn in Figur e 4-8 .
CH A P T E R 5-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 5 Configuring the Adaptive Security Appliance This chapter describes t he initial conf iguration of the ad ap ti v e sec ur it y a ppl ia nc e.
Chapter 5 Co nfiguring the Adaptive Secu rity Appliance About the Adaptive Security Device Manager 5-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 By default, the adapti ve security appliance Management interface is conf igured with a default DHCP address pool.
5-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 5 Con figuring the Adaptive Security A ppliance Before Launching the Startup Wizard In addition to it s.
Chapter 5 Co nfiguring the Adaptive Secu rity Appliance Using the Startup Wizard 5-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Using the Startup Wizard ASDM includes a Startup W izard to simplify the initial conf iguration of your adaptiv e security appliance.
5-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 5 Con figuring the Adaptive Security A ppliance What to Do Next b. In the address field of the bro wser, enter this URL: https://192 .168.1.1/ . Note T he adapti ve security appliance shi ps w it h a d ef au lt I P a dd r es s of 192.
Chapter 5 Co nfiguring the Adaptive Secu rity Appliance What to D o Next 5-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Conf igure the AIP SSM for intrusion pr.
CH A P T E R 6-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 6 Scenario: DMZ Configuration This chapter descri bes a configuration s cenario in whic h the adaptiv e sec urity appliance is used to protect network re sources located in a demilitari zed zone (DMZ).
Chapter 6 Scen ario: DMZ Configuration Example DMZ Network Topology 6-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figure 6-1 Networ k Layo ut for DMZ Configur.
6-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Example DMZ Network Topology Figur e 6-2 Outg oing HT TP T r affi c Flow.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figur e 6-3 Inc.
6-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt This confi gur.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 • For the int.
6-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt Creating IP Po.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 T o configure a.
6-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt d. From the Interf aces drop-do wn list, choose DMZ. e. T o create a ne w IP pool, enter a unique Po ol ID.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 g. Click Add to add this range of IP ad dresses to the Address Pool.
6-11 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt e. Click the Port Address T ranslation (P A T) using the IP addr ess of the interfac e radio b utton.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-12 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 The displayed conf iguration should be similar to the follo wing: Step 3 Confirm that the conf iguration values are correct.
6-13 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt In this proce.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-14 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 c. Click OK to add the Dynamic N A T Rule and return to the Conf iguration > NA T w i n do w .
6-15 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt The displayed conf iguration should be similar to the follo wing: Step 6 Click Apply to complete the adaptiv e security applia nce configuration changes.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-16 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 For man y conf.
6-17 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt Step 5 In the Static T ranslation area , specify the public IP address to be used for the web server: a.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-18 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 The displayed conf iguration should be similar to the follo wing: Step 7 Click Apply to complete the adaptiv e security applia nce configuration changes.
6-19 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt appliance tha.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-20 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 2 In the Interface and Action area: a. From the Interf ace drop-do wn list, choose Outside.
6-21 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt Alternati vely , if the address of th e source host or netw ork is preconf igured, choose the source IP address from the IP A ddress drop-do wn list.
Chapter 6 Scen ario: DMZ Configuration Configuring the Se curity Appliance for a D MZ Deployment 6-22 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 At this point, the entries in the Add Access Rule dialog box should be similar to the following: d.
6-23 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration Configuring the Security Applia nce for a DMZ Deployme nt Step 7 Click Apply to sav e the configuration changes t o the conf iguration that the adapti ve secur ity appliance is current ly running.
Chapter 6 Scen ario: DMZ Configuration What to D o Next 6-24 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 8 If you want the conf iguration changes to be sav ed to the startup configurati on so that they are applied t he next time the de vice starts, from the File menu, click Sa ve .
6-25 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 6 Scenario: DMZ Configu ration What to Do Next T o Do This .
Chapter 6 Scen ario: DMZ Configuration What to D o Next 6-26 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01.
CH A P T E R 7-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 7 Scenario: Remote-Access VPN Configuration This chapter descri bes how to use the adapti ve security appliance to accept remote-access IPsec VPN c onnections.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figur e 7.
7-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario • Spe.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Starting ASDM T o run ASDM in a web browser , enter the f actory defaul t IP address in the address fie l d : https://192.
7-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario Configu.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Selecting.
7-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario Specify.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 2 En.
7-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario In Step.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 (Optional) Configuring User Accounts If you ha ve chosen t o authenticate user s with the local user database, you can create new user accounts here.
7-11 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario Config.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-12 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 3 Click Next to continue.
7-13 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario In Step 7 of the VPN W izard, perform the follo wing steps: Step 1 Enter the netw ork conf iguration informat ion to be pushed to remote clien ts.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-14 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 T o spec.
7-15 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario Config.
Chapter 7 Scenario : Remote-Access VPN Configuration Implementing the IPsec Remote-Access VPN Scenario 7-16 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Specifyi.
7-17 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration Implementing the IPse c Remote-Access VPN Scenario Note Enable split tunnelin g b y checking the Enable Split T unneling check box at the bottom of the screen.
Chapter 7 Scenario : Remote-Access VPN Configuration What to D o Next 7-18 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 If you are satisf ied with the configuration, click Finish to apply the changes to the adaptiv e se curity appliance.
7-19 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 7 Sce nario: Remote-Access VPN Configuration What to Do Next T o Do This .
Chapter 7 Scenario : Remote-Access VPN Configuration What to D o Next 7-20 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01.
CH A P T E R 8-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 8 Scenario: Site-to-Site VPN Configuration This chapter descri bes how to use the ad apti ve security appliance to create a site-to-site VPN.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration Implementing the Site-to-Site Scenario 8-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Figur e 8-1 Networ k.
8-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 8 Sce nario: S ite-to-Site VPN Configuration Implementing the Site-to-Site Scenario Configuring the Site-to-Site VPN This section describes how to use the ASDM VPN W izard to configure the adaptiv e se curity appliance for a site-to-site VPN.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration Implementing the Site-to-Site Scenario 8-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Configuring the Secu.
8-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 8 Sce nario: S ite-to-Site VPN Configuration Implementing the Site-to-Site Scenario In Step 1 of the VPN W izard , perform the following steps: a. Click the Site-to -Site VP N radio button.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration Implementing the Site-to-Site Scenario 8-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Providing Information A bout the Remote VPN Peer The VPN peer is the system on the othe r end of the connection that you are confi guring, usually at a remote site.
8-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 8 Sce nario: S ite-to-Site VPN Configuration Implementing the Site-to-Site Scenario Step 3 Click Next to continue.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration Implementing the Site-to-Site Scenario 8-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Note When configuri ng Security Appliance 2 , enter the e xact values for each of the options that you cho se for Security Appliance 1.
8-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 8 Sce nario: S ite-to-Site VPN Configuration Implementing the Site-to-Site Scenario Configuring IPSec E.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration Implementing the Site-to-Site Scenario 8-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Specifying Hosts and Networks Identify hosts and netw orks at the local site that are permitted to use th is IPSec tunnel to communi cate with the remote-site p eer .
8-11 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 8 Sce nario: S ite-to-Site VPN Configuration Implementing the Site-to-Site Scenario Step 5 Click Next to continue.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration Implementing the Site-to-Site Scenario 8-12 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 If you want the con.
8-13 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 8 Sce nario: S ite-to-Site VPN Configuration Configuring the Other Sid e of the VPN Connection Configuring the Other Side of the VPN Connection Y ou ha ve just conf igured th e local adaptive security a ppliance.
Chapter 8 Sc enario: Si te-to-Site VPN Configuration What to D o Next 8-14 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Y o u can configure the adapti ve security appliance for more than one application.
CH A P T E R 9-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 9 Configuring the AIP SSM The optional AIP SSM runs advanced IPS so ftw are that pro vides further security inspection either in inline mode or p romiscuous mode.
Chapter 9 Configuring the AIP SSM AIP SSM Configuration 9-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 This section includes the following topics: • Overvie .
9-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 9 Configuring the AIP SSM AIP SSM Configuration T o identify traffic to div ert from the adap ti ve sec.
Chapter 9 Configuring the AIP SSM AIP SSM Configuration 9-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 The inline and promiscuous k eyw ords control the operating mode of the AIP SSM.
9-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 9 Configuring the AIP SSM AIP SSM Configuration Sessioning to the AIP SSM and Running Setup After you h.
Chapter 9 Configuring the AIP SSM AIP SSM Configuration 9-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 this product you agree to comply with applicab le laws and regulations. If you are unable to comply with U.
9-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 9 Configuring the AIP SSM What to Do Next What to Do Next Y ou are now ready to co nfig ure the adapti ve security appliance for intrusion pre vention.
Chapter 9 Configuring the AIP SSM What to D o Next 9-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Y o u can configure the adapti ve security appliance for more than one application. The follo wing sections p rovide conf iguration procedures for oth er common applications of the adap tiv e security appliance.
CH A P T E R 10-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 10 Configuring the CSC SSM The ASA 5500 series adaptiv e security appliance supports the CSC SSM, which runs Content Security and Control software. The CS C SSM provides protectio n against viruses, spyware, spam, and other unwanted traf fic.
Chapter 10 Configuring the CSC SSM About Deploying the Secur ity Appliance with the CSC SSM 10-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 In addition to o bt.
10-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM About Deploying the Sec urity Appliance with the CSC SSM Figur e 1 0-1 CSC .
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Note The CSC SSM handles SMTP traff ic some what dif ferently than other content types.
10-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security In this scenari o, the customer has deployed an adapti ve security appliance with a CSC SSM for content security .
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 I.
10-7 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security Note The SSM management port IP address must be accessible by the hosts used to run ASDM.
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-8 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 4 Click Ye s to accept the certificates. Click Ye s for all subsequent authenti cation and certif icate dialog bo xes.
10-9 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security • If you are using NTP to control time settings, v erify the NTP configurati on.
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-10 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 4 Click Next .
10-11 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security • Domain name used by the local mail serv er as the incoming domain.
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-12 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 By default, all net works ha ve managemen t access to the CSC SSM.
10-13 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security Step 11 In Step 5 of the CSC Setup W izard, enter a new password for management access.
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-14 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 13 In Step 6 of the CSC Setup W izard, re view conf iguration settings you just entered for the CSC SSM.
10-15 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security T.
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-16 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 5 Click Next. The T raffic Classif ication Criteria page appears.
10-17 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security Step 8 In the Service Polic y Rule W izard, click the CSC Scan tab .
Chapter 10 Configuring the CSC SSM Scenario: Security Ap pliance with CSC SSM Depl oyed for C ontent Security 10-18 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Step 10 Click Finish .
10-19 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM Scenario: Security Appliance with CSC SSM D eployed for Content Security The new service polic y appears in the Service Policy Rules pane.
Chapter 10 Configuring the CSC SSM What to D o Next 10-20 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 If included in the license you purchased, you can create custom settings fo r URL blocking and URL f iltering, as well as email an d FTP parameters.
10-21 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 10 Configuring the CSC SSM What to Do Next After you have conf igured the CSC SSM software, you may w.
Chapter 10 Configuring the CSC SSM What to D o Next 10-22 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01.
CH A P T E R 11-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 11 Configuring the 4GE SSM for Fiber The 4GE Security Services Module (SSM) has four Ethernet ports, and each port has two media type options: SFP (Small Form-F actor Pluggable) f iber or RJ 35.
Chapter 11 Configuring the 4GE SSM for Fiber Cabling 4GE SSM Interfaces 11-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Cabling 4GE SSM Interfaces T o ca ble 4.
11-3 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 11 Configuring the 4G E SSM for Fiber Setting the 4GE SSM Media Type for Fib er Interfaces (Optional) Figur e 1 1 -2 Connecting the LC Conn ector e. Connect the other end of t he LC connector to your netw ork de vice.
Chapter 11 Configuring the 4GE SSM for Fiber Setting the 4GE SSM Media Type for Fiber Interfaces (Optio nal) 11-4 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 Note Because the default media ty pe setting is Ethernet, y ou do not need to change the media type setting for Ethernet int erfaces you use.
11-5 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 Chapter 11 Configuring the 4G E SSM for Fiber What to Do Next What to Do Next Y ou have co mpleted the initial conf iguration. Y ou may want to consider performing some of the follo wing additional step s: T o Do This .
Chapter 11 Configuring the 4GE SSM for Fiber What to D o Next 11-6 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01.
CH A P T E R A-1 Cisco ASA 5500 Series Adaptive Securi ty Appliance Getting Started Guide 78-17611-01 A Obtaining a DES License or a 3DES-AES License Cisco adapti ve security appl iances are av ailabl.
Chapter A Obtaining a DE S License o r a 3DES-AES License A-2 Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 T o use the activ ation ke y , perform the foll owing steps: Command Purpose Step 1 hostname# show version Sho ws the software release, hardware conf iguration, license k ey , and related uptime data.
Un point important après l'achat de l'appareil (ou même avant l'achat) est de lire le manuel d'utilisation. Nous devons le faire pour quelques raisons simples:
Si vous n'avez pas encore acheté Cisco Systems ASA 5500 c'est un bon moment pour vous familiariser avec les données de base sur le produit. Consulter d'abord les pages initiales du manuel d'utilisation, que vous trouverez ci-dessus. Vous devriez y trouver les données techniques les plus importants du Cisco Systems ASA 5500 - de cette manière, vous pouvez vérifier si l'équipement répond à vos besoins. Explorant les pages suivantes du manuel d'utilisation Cisco Systems ASA 5500, vous apprendrez toutes les caractéristiques du produit et des informations sur son fonctionnement. Les informations sur le Cisco Systems ASA 5500 va certainement vous aider à prendre une décision concernant l'achat.
Dans une situation où vous avez déjà le Cisco Systems ASA 5500, mais vous avez pas encore lu le manuel d'utilisation, vous devez le faire pour les raisons décrites ci-dessus,. Vous saurez alors si vous avez correctement utilisé les fonctions disponibles, et si vous avez commis des erreurs qui peuvent réduire la durée de vie du Cisco Systems ASA 5500.
Cependant, l'un des rôles les plus importants pour l'utilisateur joués par les manuels d'utilisateur est d'aider à résoudre les problèmes concernant le Cisco Systems ASA 5500. Presque toujours, vous y trouverez Troubleshooting, soit les pannes et les défaillances les plus fréquentes de l'apparei Cisco Systems ASA 5500 ainsi que les instructions sur la façon de les résoudre. Même si vous ne parvenez pas à résoudre le problème, le manuel d‘utilisation va vous montrer le chemin d'une nouvelle procédure – le contact avec le centre de service à la clientèle ou le service le plus proche.