Sunday, June 22, 2014

ASA IPS, AVC, WSE and Botnet filter on ASA 5585-X at the same time.



The Cisco® Advanced Inspection and Prevention Security Services Module (AIP-SSM) for the Cisco ASA 5500 Series Adaptive Security Appliance provides proactive, full-featured intrusion prevention services to stop malicious traffic, including worms and network viruses, before they can affect your network.

AIP-SSM Intrusion Prevention Services

Using Cisco IPS Sensor Software Version 6.x, the Cisco AIP-SSM combines inline prevention services with innovative technologies to improve accuracy. The result is total confidence in the protection offered by your intrusion prevention system (IPS) solution, without the fear of legitimate traffic being dropped. When deployed within Cisco ASA 5500 Series appliances, the AIP-SSM offers comprehensive protection of your network by collaborating with other network security resources, providing a proactive approach to protecting your network. The Cisco AIP SSM helps users stop threats with greater confidence through the use of:
  • Accurate inline prevention technologies—Provides unparalleled ability to take preventive action against a broader range of threats without the risk of dropping legitimate traffic. These unique technologies offer intelligent, automated, contextual analysis of your data and help ensure you are getting the most out of your intrusion prevention solution.
  • Multivector threat identification—Protects your network from policy violations, vulnerability exploitations, and anomalous activity through detailed inspection of traffic in Layers 2 through 7.
  • Unique network collaboration—Enhances scalability and resiliency through network collaboration, including efficient traffic capture techniques, load-balancing capabilities, and visibility into encrypted traffic.
  • Powerful management, event correlation, and support services—Enables a complete solution, including configuration, management, data correlation, and advanced support services. In particular, the Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS) identifies, isolates, and recommends precision removal of offending elements, for a networkwide intrusion prevention solution. And the Cisco Incident Control System (ICS) prevents new worm and virus outbreaks by enabling the network to rapidly adapt and provide a distributed response.
When combined, these elements provide a comprehensive inline prevention solution, giving you the confidence to detect and stop the broadest range of malicious traffic before your business continuity is affected.

https://supportforums.cisco.com/discussion/12086801/ips-avc-wse-and-botnet-filter-asa-5585-x-same-time

http://www.cisco.com/c/en/us/products/interfaces-modules/asa-advanced-inspection-prevention-aip-security-services-module/index.html

GNS3 is an open source software (under GPL) that simulate complex networks while being as close as possible to the way real networks perform. All of this without having dedicated network hardware such as routers and switches.

GNS3 is an open source software (under GPL) that simulate complex networks while being as close as possible to the way real networks perform. All of this without having dedicated network hardware such as routers and switches.
Our software provides an intuitive graphical user interface to design and configure virtual networks, it runs on traditional PC hardware and may be used on multiple operating systems, including Windows, Linux, and MacOS X.
In order to provide complete and accurate simulations, GNS3 actually uses the following emulators to run the very same operating systems as in real networks:
  • Dynamips, the well known Cisco IOS emulator.
  • VirtualBox, runs desktop and server operating systems as well as Juniper JunOS.
  • Qemu, a generic open source machine emulator, it runs Cisco ASA, PIX and IPS
  •  
  • Who can use it?

    GNS3 is an excellent alternative or complementary tool to real labs for network engineers, administrators and people studying for certifications such as Cisco CCNA, CCNP and CCIE as well as Juniper JNCIA, JNCIS and JNCIE. Open source networking is supported too!
    It can also be used to experiment with features or to check configurations that need to be deployed later on real devices.
    Our program includes exciting features, for instance connection of your virtual network to real ones or packet captures using Wireshark.
    Finally, thanks to the VirtualBox support, even system administrators and engineers can take advantage of GNS3 to make labs, test network features and study for Redhat (RHCE, RHCT) and Microsoft (MSCE, MSCA) certifications to name a few.

    Where do I start?

    In most situations, to use GNS3 you first need to provide your own copy of a network operating system, like Cisco IOS, PIX, ASA, IPS or Juniper JunOS. Here is a complete list of what hardware is emulated by GNS3. We also suggest ready to use non-copyrighted appliances.
    Once you have your operating system, you can start reading our documentation and learn how to use GNS3. Watching video tutorials is also a good way to better understand the program. Please note that to GNS3 might be daunting for beginners, you will need patience and practice. Our community is ready to help you on our forum and social media sites.http://www.gns3.net/
     

RouterOS is the operating system of RouterBOARD. It can also be installed on a PC and will turn it into a router with all the necessary features - routing, firewall, bandwidth management, wireless access point, backhaul link, hotspot gateway, VPN server and more.

Learn how solutions from Nagios can address everyday problems and solve your toughest IT challenges

Cacti is a complete network graphing solution designed to harness the power of RRDTool's data storage and graphing functionality. Cacti provides a fast poller, advanced graph templating, multiple data acquisition methods, and user management features out of the box. All of this is wrapped in an intuitive, easy to use interface that makes sense for LAN-sized installations up to complex networks with hundreds of devices. http://www.cacti.net/