jheary
Distinguished Systems Engineer

Cisco Introduces IPS Card for the ASA 5505

Analysis
Apr 22, 20093 mins

Ever wondered what that blank slot in your ASA5505 is for? Well now you know, it’s for a modular IPS card. Adding full-blown IPS to the ASA5505 will substantially increase its ability to protect you. The AIP SSC-5 provides up to 75 Mbps of IPS or IDS throughput and supports both IPv4 and IPv6 networks. The 75Mbps performance with 4000 maximum connections per second should be able to accommodate just about any SOHO or branch office configuration, the sweet spot for the ASA5505.

The AIP SSC-5 does not have any physical ports on it so management is done through the ASA management ports. You can either use CLI, IME, or ASDM to configure and monitor the card. The IPS card can be deployed in either Inline or promiscuous mode. Inline mode is the most secure because it places the IPS directly into the traffic flow. You can use policies to determine what traffic you want to redirect to the IPS card and what you don’t. If you put the IPS card in promiscuous mode then the ASA will just send copies of the traffic to the card. Very much like what you get with a span port on a switch. The AIP SSC-5 supports the same signature set as its larger Cisco IPS appliance brethren. In fact, the IPS 6.2 code on the AIP card is almost the same as that of Cisco IPS appliances. There are a few features that Cisco took out of the SSC-5 due to its limited form factor. The Cisco AIP SSC-5 does not support Cisco Global Correlation, Cisco Anomaly Detection, sensor virtualization, or custom signatures. Additionally, you will not be able to un-retire default retired signatures. A retired signature is one that Cisco has decided is too outdated to be of much use anymore. For all practical purposes customers shouldn’t be un-retiring signatures on any Cisco IPS platform so this shouldn’t be a big deal. So will you start to retrofit your Cisco ASA 5505’s with the IPS module? What type of module would you like to have next for the platform? ASA Datasheet is here ASA Q&A page: http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/qa_c67-525310.html Orderability should be turned on in May. Here are the part numbers:

The opinions and information presented here are my PERSONAL views and not those of my employer. I am in no way an official spokesperson for my employer.

More from Jamey Heary: Credit Card Skimming: How thieves can steal your card info without you knowing it Cisco enters the crowded AV and DLP client marketCisco’s new ASA code allows you to securely take your Cisco IP Phone with you anywhereCisco targets Symantec, McAfee with its new antivirus client Google’s Chrome raises security concerns and tastes like chicken feet a>Go to Jamey’s Blog for more articles on security.

*

*

*

*

*

jheary

Jamey Heary, CCIE #7680, is a Distinguished Systems Engineer at Cisco Systems. Jamey sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey has authored several security books, his latest is Cisco ISE for BYOD and Secure Unified Access. He also has a patent on a new DDoS mitigation and firewall IP reputation technique. Jamey leads numerous security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is also recognized as a Distinguished Speaker at Cisco Live. He has been working in the IT field for 19 years and in IT security for 15 years.

More from this author