Summary of the content on the page No. 1
Cisco ASA 5500 Series Adaptive
Security Appliance Getting Started
Guide
For the Cisco ASA 5510, ASA 5520, and ASA 5540
Corporate Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 526-4100
Customer Order Number: DOC-7817611=
Text Part Number: 78-17611-01
Summary of the content on the page No. 2
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE I
Summary of the content on the page No. 3
CONTENTS CHAPTER 1 Before You Begin 1-1 ASA 5500 1-1 ASA 5500 with AIP SSM 1-2 ASA 5500 with CSC SSM 1-3 ASA 5500 with 4GE SSM 1-4 CHAPTER 2 Installing the Cisco ASA 5500 2-1 Verifying the Package Contents 2-2 Installing the Chassis 2-3 Rack-Mounting the Chassis 2-4 Ports and LEDs 2-5 What to Do Next 2-9 CHAPTER 3 Installing Optional SSMs 3-1 Cisco 4GE SSM 3-1 4GE SSM Components 3-2 Installing the Cisco 4GE SSM 3-3 Installing the SFP Modules 3-4 SFP Module 3-5 Installing the SFP Module 3-6 Cisco
Summary of the content on the page No. 4
Contents CHAPTER 4 Connecting Interface Cables 4-1 Connecting Cables to Interfaces 4-2 What to Do Next 4-10 CHAPTER 5 Configuring the Adaptive Security Appliance 5-1 About the Factory-Default Configuration 5-1 About the Adaptive Security Device Manager 5-2 Before Launching the Startup Wizard 5-3 Using the Startup Wizard 5-4 What to Do Next 5-5 CHAPTER 6 Scenario: DMZ Configuration 6-1 Example DMZ Network Topology 6-1 Configuring the Security Appliance for a DMZ Deployment 6-4 Configuration Requi
Summary of the content on the page No. 5
Contents Starting ASDM 7-4 Configuring the FWSM for an IPsec Remote-Access VPN 7-5 Selecting VPN Client Types 7-6 Specifying the VPN Tunnel Group Name and Authentication Method 7-7 Specifying a User Authentication Method 7-8 (Optional) Configuring User Accounts 7-10 Configuring Address Pools 7-11 Configuring Client Attributes 7-12 Configuring the IKE Policy 7-13 Configuring IPsec Encryption and Authentication Parameters 7-15 Specifying Address Translation Exception and Split Tunneling 7-16 Verif
Summary of the content on the page No. 6
Contents CHAPTER 9 Configuring the AIP SSM 9-1 AIP SSM Configuration 9-1 Overview of Configuration Process 9-2 Configuring the ASA 5500 to Divert Traffic to the AIP SSM 9-2 Sessioning to the AIP SSM and Running Setup 9-5 What to Do Next 9-7 CHAPTER 10 Configuring the CSC SSM 10-1 About the CSC SSM 10-1 About Deploying the Security Appliance with the CSC SSM 10-2 Scenario: Security Appliance with CSC SSM Deployed for Content Security 10-4 Configuration Requirements 10-5 Configuring the CSC SSM fo
Summary of the content on the page No. 7
CH A P T E R 1 Before You Begin Use the following table to find the installation and configuration steps that are required for your implementation of the adaptive security appliance. The adaptive security appliance implementations included in this document are as follows: • ASA 5500, page 1-1 ASA 5500 with AIP SSM, page 1-2 ASA 5500 with CSC SSM, page 1-3 ASA 5500 with 4GE SSM, page 1-4 ASA 5500 To Do This ... See ... Install the chassis Chapter 2, “Installing the Cisco ASA 5500” Con
Summary of the content on the page No. 8
Chapter 1 Before You Begin ASA 5500 with AIP SSM To Do This ... (continued) See ... Configure the adaptive security appliance for Chapter 6, “Scenario: DMZ your implementation Configuration” Chapter 7, “Scenario: Remote-Access VPN Configuration” Chapter 8, “Scenario: Site-to-Site VPN Configuration” Configure optional and advanced features Cisco Security Appliance Command Line Configuration Guide Operate the system on a daily basis Cisco Security Appliance Command Reference Cisco Sec
Summary of the content on the page No. 9
Chapter 1 Before You Begin ASA 5500 with CSC SSM To Do This .... (continued) See .... Configure IPS software for intrusion Configuring the Cisco Intrusion prevention Prevention System Sensor Using the Command Line Interface Cisco Intrusion Prevention System Command Reference Refine configuration and configure optional Cisco Security Appliance Command and advanced features Line Configuration Guide Cisco Security Appliance Command Reference Cisco Security Appliance Logging Configurati
Summary of the content on the page No. 10
Chapter 1 Before You Begin ASA 5500 with 4GE SSM To Do This .... (continued) To Do This .... Configure the CSC SSM Cisco Content Security and Control SSM Administrator Guide Refine configuration and configure Cisco Security Appliance Command optional and advanced features Line Configuration Guide Cisco Security Appliance Command Reference Cisco Security Appliance Logging Configuration and System Log Messages ASA 5500 with 4GE SSM To Do This ... See ... Install the chassis Chapter 2,
Summary of the content on the page No. 11
CH A P T E R 2 Installing the Cisco ASA 5500 Warning Only trained and qualified personnel should be allowed to install, replace, or service this equipment. Caution Read the safety warnings in the Regulatory Compliance and Safety Information for the Cisco ASA 5500 Series and follow proper safety procedures when performing these steps. This chapter describes the product overview, memory requirements and rack-mount and installation procedures for the adaptive security appliance. This chapte
Summary of the content on the page No. 12
MGMT USB2 USB1 Safety and Compliance Guide Cisco ASA 5500 Adaptive Security Appliance Product CD FLASH LINK SPD LINK SPD LINK SPD LINK SPD 3 2 1 0 Chapter 2 Installing the Cisco ASA 5500 Verifying the Package Contents Verifying the Package Contents Verify the contents of the packing box to ensure that you have received all items necessary to install your Cisco ASA 5500 series adaptive security appliance. See Figure 2-1. Figure 2-1 Contents of ASA 5500 Package Cisco ASA 5500 adapti
Summary of the content on the page No. 13
Chapter 2 Installing the Cisco ASA 5500 Installing the Chassis Installing the Chassis This section describes how to rack-mount and install the adaptive security appliance. You can mount the adaptive security appliance in a 19-inch rack (with a 17.5- or 17.75-inch opening). Warning To prevent bodily injury when mounting or servicing this unit in a rack, you must take special precautions to ensure that the system remains stable. The following guidelines are provided to ensure your safet
Summary of the content on the page No. 14
Chapter 2 Installing the Cisco ASA 5500 Installing the Chassis Rack-Mounting the Chassis To rack-mount the chassis, perform the following steps: Step 1 Attach the rack-mount brackets to the chassis using the supplied screws. Attach the brackets to the holes as shown in Figure 2-2. After the brackets are secured to the chassis, you can rack-mount it. Figure 2-2 Installing the Right and Left Brackets Step 2 Attach the chassis to the rack using the supplied screws, as shown in Figure 2-3.
Summary of the content on the page No. 15
C SA 0 I a e Se A e POWERSTATUS FLASH ISCO A 554 SER ES Ad ptiv curity pplianc ACTIVEVPN Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs Figure 2-3 Rack-Mounting the Chassis To remove the chassis from the rack, remove the screws that attach the chassis to the rack, and then remove the chassis. Ports and LEDs This section describes the front and rear panels. Figure 2-4 shows the front panel LEDs. Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01
Summary of the content on the page No. 16
Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs Figure 2-4 Front Panel LEDs CISCO ASA 5540 SERIES Adaptive Security Appliance POWER STATUS ACTIVE VPN FLASH 1 3 5 2 4 LED Color State Description 1 Power Green On The system has power. 2 Status Green Flashing The power-up diagnostics are running or the system is booting. Solid The system has passed power-up diagnostics. Amber Solid The power-up diagnostics have failed. 3 Active Green Solid This is the active failover device. Amber So
Summary of the content on the page No. 17
CONSOLE AUX MGMT USB2 USB1 Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs Figure 2-5 shows the rear panel features for the adaptive security appliance. Figure 2-5 Rear Panel LEDs and Ports (AC Power Supply Model Shown) 1 2 3 4 5 FLASH LINK SPD LINK SPD LINK SPD LINK SPD 3 2 1 0 6 8 10 12 14 7 13 9 11 1 2 1 Management Port 6 USB 2.0 interfaces 11 VPN LED 3 2 External CompactFlash slot 7 Network interfaces 12 Flash LED 3 Serial Console port 8 Power indicator LED 13 AUX port 4 P
Summary of the content on the page No. 18
USB2 USB1 MGMT Chapter 2 Installing the Cisco ASA 5500 Ports and LEDs Figure 2-6 shows the adaptive security appliance rear panel LEDs. Figure 2-6 Rear Panel Link and Speed Indicator LEDs 1 2 LNK SPD LNK SPD LNK SPD LNK SPD 3 2 1 0 1 MGMT indicator LEDs 2 Network interface LEDs Table 2-1 lists the rear MGMT and Network interface LEDs. Table 2-1 Link and Speed LEDs Indicator Color Description Left side Solid green Physical link Green flashing Network activity Right side Not lit 10 Mbps
Summary of the content on the page No. 19
Chapter 2 Installing the Cisco ASA 5500 What to Do Next What to Do Next Continue with one of the following chapters: To Do This ... See ... Install SSMs you purchased but that Chapter 3, “Installing Optional SSMs” have not yet been installed Continue with connecting interface Chapter 4, “Connecting Interface cables Cables” Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 2-9
Summary of the content on the page No. 20
Chapter 2 Installing the Cisco ASA 5500 What to Do Next Cisco ASA 5500 Series Adaptive Security Appliance Getting Started Guide 78-17611-01 2-10