


 



<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docwiki.cisco.com/w/skins/common/feed.css?270"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;feed=atom&amp;action=history</id>
		<title>Iron Port Email Security Appliances and ACE Module Configuration Example - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;action=history"/>
		<updated>2013-05-26T09:08:57Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.16.0</generator>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=24589&amp;oldid=prev</id>
		<title>Docwikibot: Bot: Adding {{Template:Required Metadata}}</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=24589&amp;oldid=prev"/>
				<updated>2009-12-18T17:30:27Z</updated>
		
		<summary type="html">&lt;p&gt;Bot: Adding {{Template:Required Metadata}}&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 17:30, 18 December 2009&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;{{Template:Required Metadata}}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Summary==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Summary==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;As communications infrastructures continue to evolve,&amp;nbsp; email has become a critical component to business processes. The level of sophistication of what has come to be known as Spam Mail and Virus/Trojan applications have also evolved. Many companies now regularly report that up to 90% of in-bound email messaging has nothing to do with business. To deal with this issue that impacts not only available bandwidth resources, but also message storage on Servers and SANs, companies both large and small have turned to Email Security and Scanning solutions to minimize the impact of malicious email.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;As communications infrastructures continue to evolve,&amp;nbsp; email has become a critical component to business processes. The level of sophistication of what has come to be known as Spam Mail and Virus/Trojan applications have also evolved. Many companies now regularly report that up to 90% of in-bound email messaging has nothing to do with business. To deal with this issue that impacts not only available bandwidth resources, but also message storage on Servers and SANs, companies both large and small have turned to Email Security and Scanning solutions to minimize the impact of malicious email.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Docwikibot</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=20071&amp;oldid=prev</id>
		<title>Gdufour: /* Overview */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=20071&amp;oldid=prev"/>
				<updated>2009-08-13T11:39:07Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Overview&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 11:39, 13 August 2009&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 37:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 37:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; resource-class IP-rsc&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; resource-class IP-rsc&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; limit-resource sticky minimum &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;0.05 &lt;/del&gt;maximum &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;unlimited &lt;/del&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; limit-resource sticky minimum &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;5 &lt;/ins&gt;maximum &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;equal-to-min&lt;/ins&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;(required since sticky [session persistence] is required for the solution)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;(required since sticky [session persistence] is required for the solution&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;. The sticky resource does not grow between a min and a max like the other ones. It will allocate the minimum and this is all you get. So make sure you allocate enough sticky resource.&lt;/ins&gt;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Gdufour</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=7912&amp;oldid=prev</id>
		<title>Pzimmerm: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=7912&amp;oldid=prev"/>
				<updated>2008-12-04T18:37:28Z</updated>
		
		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 18:37, 4 December 2008&lt;/td&gt;
		&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Pzimmerm</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=7911&amp;oldid=prev</id>
		<title>Pzimmerm: /* Overview */</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=Iron_Port_Email_Security_Appliances_and_ACE_Module_Configuration_Example&amp;diff=7911&amp;oldid=prev"/>
				<updated>2008-12-03T21:06:26Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Overview&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Summary==&lt;br /&gt;
As communications infrastructures continue to evolve,  email has become a critical component to business processes. The level of sophistication of what has come to be known as Spam Mail and Virus/Trojan applications have also evolved. Many companies now regularly report that up to 90% of in-bound email messaging has nothing to do with business. To deal with this issue that impacts not only available bandwidth resources, but also message storage on Servers and SANs, companies both large and small have turned to Email Security and Scanning solutions to minimize the impact of malicious email.&lt;br /&gt;
&lt;br /&gt;
IronPort email security appliances combine market-leading, best-of-breed anti-spam, antivirus, encryption, digital rights management, and archiving technologies. These solutions run on IronPort’s revolutionary MTA platform, providing the highest levels of email protection, with exclusive preventive and reactive technologies, and industry-leading email management tools.&lt;br /&gt;
&lt;br /&gt;
When coupled with the Application Control Engine, the solution now scales to meet virtually any size solution. ACE brings high-availability and additional levels of security to the overall solution. The Cisco ACE, either the module for Catalyst 6500 chassis, or the 4710 Appliance provide industry leading capabilities including virtual execution environments, roles-based administration, and scalability via licenses not forklift hardware changes.&lt;br /&gt;
&lt;br /&gt;
==Overview==&lt;br /&gt;
&lt;br /&gt;
This document will discuss a particular deployment of IronPort C-Series appliances along with ACE. The ACE provided the High Availability environment for a total deployment of 4 Iron Port appliances. It was also inserted into the data path without impact to the existing infrastructure.&lt;br /&gt;
&lt;br /&gt;
The flexibility for deployment of ACE, coupled with industry leading features has positioned this deployment to be one of  over 100 applications to be addressed at this particular customer.  The base infrastructure of this installation looks like this:&lt;br /&gt;
&lt;br /&gt;
[[Image:Iron Port and ACE.jpg]]&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Of note are the blue links that are 802.1Q trunks allowing the transparent Firewalls to provide L2 access to the Edge Catalyst 6509 switches, thus the ACE VIP is a Public IP address.&lt;br /&gt;
&lt;br /&gt;
Prior to adding ACE into this solution the customer needed a way to effectively provide High Availability for email scanning via the IronPort appliances. ACE effectively provided not only the Virtual IP address, but also enforced additional security features into the solution which were not provided by the Firewalls or existing infrastructure.&lt;br /&gt;
These additional security features include the ability to enforce TCP/IP Normalizations for &lt;br /&gt;
&lt;br /&gt;
* Bad segment checksum&lt;br /&gt;
* Bad TCP header or payload length&lt;br /&gt;
* Suspect TCP flags (for example, NULL, SYN/FIN, or FIN/URG)&lt;br /&gt;
&lt;br /&gt;
These are on by default and are handled at the VLAN interface. ACE will always drop this traffic and can be configured for more in-depth protocol enforcement via parameter maps. In addition, ACE also employs ICMP-Guard, SYN-Cookie (Anti-DDoS), IP TTL, and uRPF for securing the overall environment.&lt;br /&gt;
&lt;br /&gt;
ACE utilizes device virtualization by means of contexts, much the same as the Firewall Services Module and ASA products. Each of these contexts provides an independent execution space for packet and flow processing. The Admin context acts much like the Control Plane for the ACE device as it is where other contexts are defined, failover options for High Availability, and devices resources are configured and provided to other virtual contexts. Here is the Admin context configuration for this  solution: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;SF_ACE/Admin# show running-config&lt;br /&gt;
  Generating configuration....&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  login timeout 0&lt;br /&gt;
  hostname SF_ACE&lt;br /&gt;
  boot system image:c6ace-t1k9-mz.A2_1_1.bin(ACE module ver. 2.1)&lt;br /&gt;
  &lt;br /&gt;
  resource-class IP-rsc&lt;br /&gt;
    limit-resource sticky minimum 0.05 maximum unlimited &amp;lt;/pre&amp;gt;&lt;br /&gt;
(required since sticky [session persistence] is required for the solution)&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &amp;lt;pre&amp;gt;class-map type management match-any remote-access&lt;br /&gt;
    2 match protocol ssh any&lt;br /&gt;
    3 match protocol snmp any&lt;br /&gt;
    4 match protocol https any&lt;br /&gt;
    5 match protocol telnet any&lt;br /&gt;
    6 match protocol icmp any&lt;br /&gt;
  &lt;br /&gt;
  policy-map type management first-match remote-mgmt&lt;br /&gt;
    class remote-access&lt;br /&gt;
      permit&lt;br /&gt;
  &lt;br /&gt;
  interface vlan 207&lt;br /&gt;
    description Management Side&lt;br /&gt;
    ip address x.x.207.21 255.255.255.0&lt;br /&gt;
    peer ip address x.x.207.22 255.255.255.0&lt;br /&gt;
    alias address x.x.207.20&lt;br /&gt;
    service-policy input remote-mgmt&lt;br /&gt;
    no shutdown&lt;br /&gt;
  &lt;br /&gt;
  ip route 0.0.0.0 0.0.0.0 x.x.207.1&lt;br /&gt;
  &lt;br /&gt;
  context IronPort&lt;br /&gt;
    allocate-interface vlan 208&lt;br /&gt;
    member IP-rsc &amp;lt;/pre&amp;gt;&lt;br /&gt;
(tying resource-class to the context)&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;pre&amp;gt;username admin password 5 (removed)  role Admin &lt;br /&gt;
  domain default-domain&lt;br /&gt;
  username www password 5 (removed)  role Admin domain default-domain&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
In order to properly segment the traffic from the Admin context (Control Plane) a context called IronPort was created as shown above. Here is the configuration of the IronPort context:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;SF_ACE/IronPort# show running-config&lt;br /&gt;
  Generating configuration....&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  access-list ALL line 10 extended permit ip any any&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
 probe tcp IP-pro&lt;br /&gt;
  description IronPort Probe&lt;br /&gt;
  port 25&lt;br /&gt;
  interval 10&lt;br /&gt;
  faildetect 5&lt;br /&gt;
  passdetect interval 15&lt;br /&gt;
  passdetect count 5&lt;br /&gt;
  receive 20  &amp;lt;/pre&amp;gt;&lt;br /&gt;
(Provides a keepalive probe every 10 seconds and expects a response within 20 seconds. If an IronPort is off-line, it will be put back into service after 75 seconds from initial good contact on port 25)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;  rserver host IP1&lt;br /&gt;
    ip address x.x.208.225&lt;br /&gt;
    inservice&lt;br /&gt;
  rserver host IP2&lt;br /&gt;
    ip address x.x.208.226&lt;br /&gt;
    inservice&lt;br /&gt;
  rserver host IP3&lt;br /&gt;
    ip address x.x.208.230&lt;br /&gt;
    inservice&lt;br /&gt;
  &lt;br /&gt;
  serverfarm host IP_SF&lt;br /&gt;
    predictor least-conns&lt;br /&gt;
   probe IP-pro&lt;br /&gt;
    rserver IP1&lt;br /&gt;
      inservice&lt;br /&gt;
    rserver IP2&lt;br /&gt;
      inservice&lt;br /&gt;
    rserver IP3&lt;br /&gt;
      inservice&lt;br /&gt;
  &lt;br /&gt;
  sticky ip-netmask 255.255.255.0 address source STICKY-grp&lt;br /&gt;
    timeout 120 (suggested max timeout for IronPort sessions)&lt;br /&gt;
    replicate sticky(insures that sessions are sent to the same server)&lt;br /&gt;
    serverfarm IP_SF (ties the sticky sessions to the serverfarm)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  &lt;br /&gt;
  class-map match-any IPVIP-cls&lt;br /&gt;
    2 match virtual-address x.x.208.233 tcp eq smtp (mail traffic only)                                      &lt;br /&gt;
  class-map type management match-any MGMT-cls&lt;br /&gt;
    3 match protocol https any&lt;br /&gt;
    4 match protocol icmp any&lt;br /&gt;
    5 match protocol snmp any&lt;br /&gt;
    6 match protocol ssh any&lt;br /&gt;
    7 match protocol telnet any&lt;br /&gt;
    8 match protocol http (required for Iron Port updates)&lt;br /&gt;
  &lt;br /&gt;
  policy-map type management first-match MGMT-pol&lt;br /&gt;
    class MGMT-cls&lt;br /&gt;
      permit&lt;br /&gt;
  &lt;br /&gt;
  policy-map type loadbalance first-match IPLB-pol&lt;br /&gt;
    class class-default&lt;br /&gt;
      sticky-serverfarm STICKY-grp&lt;br /&gt;
  &lt;br /&gt;
  policy-map multi-match IPVIP-pol&lt;br /&gt;
    class IPVIP-cls&lt;br /&gt;
      loadbalance vip inservice&lt;br /&gt;
      loadbalance policy IPLB-pol&lt;br /&gt;
      loadbalance vip icmp-reply active&lt;br /&gt;
      nat dynamic 1 vlan 208 &amp;lt;/pre&amp;gt;&lt;br /&gt;
(SNAT required due to one-armed mode for traffic to return correctly to ACE from Iron Port appliances)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;  service-policy input MGMT-pol&lt;br /&gt;
  access-group input ALL&lt;br /&gt;
  (putting both in the global configs means they apply to all interfaces)&lt;br /&gt;
&lt;br /&gt;
  interface vlan 208&lt;br /&gt;
    ip address x.x.208.252 255.255.255.0&lt;br /&gt;
    peer ip address x.x.208.251 255.255.255.0&lt;br /&gt;
    alias address x.x.208.250&lt;br /&gt;
    nat-pool 1 x.x.208.253 x.x.208.253 netmask 255.255.255.0 pat&lt;br /&gt;
    service-policy input IPVIP-pol&lt;br /&gt;
    no shutdown&lt;br /&gt;
  &lt;br /&gt;
  ip route 0.0.0.0 0.0.0.0 x.x.208.1&amp;lt;/pre&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
Of interest to note is the One-Armed configuration of the IronPort context above. This was provided to minimize the impact to the existing environment as the IronPort appliances are accompanied by other devices on that segment. As previously mentioned, SNAT is used to insure that traffic on port 25 destined to the Iron Port appliances is returned to the ACE and not the default gateway which is x.x.208.1.&lt;br /&gt;
Also note that the base ACE security features are enabled on the VLAN208 interface, Normalizations and ICMP-Guard. These are features not provided by the transparent firewall at the Internet Edge.&lt;br /&gt;
&lt;br /&gt;
==Conclusion==&lt;br /&gt;
The combination of IronPort and ACE products makes for a compelling event for many customers. Iron Port providing, in this case, email security and ACE providing the scalability and high availability with minimal impact to the existing infrastructure. This also positions the customer to grow the applications serviced in a similar mode by ACE with additional features and operations not mentioned here and each in their logical execution space via virtual contexts. All this while scaling from the current 4Gbps throughput license to 16Gbps, 15,000 SSL transactions per second, and up to 250 virtual contexts without upgrading hardware.&lt;br /&gt;
&lt;br /&gt;
==Related Information==&lt;br /&gt;
[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp; Documentation - Cisco Systems]&lt;br /&gt;
&lt;br /&gt;
ACE:&lt;br /&gt;
http://www.cisco.com/en/US/products/ps6906/index.html&lt;br /&gt;
&lt;br /&gt;
http://www.cisco.com/en/US/products/ps6906/tsd_products_support_model_home.html&lt;br /&gt;
&lt;br /&gt;
IronPort:&lt;br /&gt;
http://www.ironport.com/products/email_security_appliances.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--List links to related information--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Data Center Application Services Configuration Examples]]&lt;/div&gt;</summary>
		<author><name>Pzimmerm</name></author>	</entry>

	</feed>