1-7
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the ASA CX Module
Configuring the ASA CX Module
Connecting the ASA CX Management Interface
In addition to providing management access to the ASA CX module, the ASA CX management interface
needs access to an HTTP proxy server or a DNS server and the Internet for signature updates and more.
This section describes recommended network configurations. Your network may differ.
The ASA CX module includes a separate management and console interface from the ASA. For initial
setup, you can connect with SSH to the ASA CX Management 1/0 interface using the default IP address
(192.168.8.8/24). If you cannot use the default IP address, you can either use the console port or use
ASDM to change the management IP address so you can use SSH.
If you have an inside router
If you have an inside router, you can route between the management network, which can include both
the ASA Management 0/0 and ASA CX Management 1/0 interfaces, and the ASA inside network for
Internet access. Be sure to also add a route on the ASA to reach the Management network through the
inside router.
ASA 5585-X
PWR
BOOT
ALARM
ACT
VPN
PS1
HDD1
PS0
HDD0
USB
RESET
0
SFP1
SFP0
101234567
MGMT
0
1
AUX CON SOLE
PWR
BOOT
ALARM
ACT
VPN
PS1
HDD1
PS0
HDD0
USB
RESET
0
SFP1
SFP0
101234567
MGMT
0
1
AUX CON SOLE
ASA Management 0/0
Default IP: 192.168.1.1
ASA CX Management 1/0
Default IP: 192.168.8.8
SSP
ASA CX SSP
334655
ASA Management 0/0
Internet
Management PC
Proxy or DNS Server (for example)
Router
ASA
ASA CX Management 1/0
Outside
CX
Management
Inside
ASA CX Default
Gateway
ASA gateway for Management
334657