<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA with Firepower module in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918135#M1010448</link>
    <description>&lt;P&gt;Thanks for help john, also i want traffic going to firepower should be in monitoring only, dont want any action/filter so that i could monitor initially what type or category of traffic flowing.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2019 12:22:41 GMT</pubDate>
    <dc:creator>Anukalp S</dc:creator>
    <dc:date>2019-09-03T12:22:41Z</dc:date>
    <item>
      <title>ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3917945#M1010446</link>
      <description>&lt;P&gt;Hi.. I have been running cisco ASA 5545 X with firepower module installed, it has two storage device with model number- Micron_M600 ( not sure if it is SSD). However firepower module has setup and is showing up(ver 6.2.0).&lt;/P&gt;&lt;P&gt;I will be going to build FMC also to manage it.&lt;/P&gt;&lt;P&gt;I need your help to guide me to send traffic in/out from ASA towards firepower so that traffic could get inspect, policies could get applied on traffic through firepower.&lt;/P&gt;&lt;P&gt;Please suggest in what should i accomplish it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 06:45:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3917945#M1010446</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-03T06:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918018#M1010447</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;you'll need to redirect traffic to the ASA FP module, add/register device to FMC, apply NGFW license feature in FMC and create your access control policies/rules.&lt;/P&gt;&lt;P&gt;see helpful link:&lt;/P&gt;&lt;P&gt;&lt;A href="http://wannabecybersecurity.blogspot.com/2019/01/cisco-asa-firepower-traffic-redirection.html" target="_blank"&gt;http://wannabecybersecurity.blogspot.com/2019/01/cisco-asa-firepower-traffic-redirection.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 08:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918018#M1010447</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-09-03T08:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918135#M1010448</link>
      <description>&lt;P&gt;Thanks for help john, also i want traffic going to firepower should be in monitoring only, dont want any action/filter so that i could monitor initially what type or category of traffic flowing.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 12:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918135#M1010448</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-03T12:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918149#M1010449</link>
      <description>&lt;P&gt;you can leverage the FMC 'network discovery' and/or configure access rule to allow all traffic and enable logging to monitor your user traffic/application.&lt;/P&gt;&lt;P&gt;you typically want to observe traffic for at least 30 days (1 month) before applying your NGFW policies, i.e. URL filter, anti-malware, etc.&lt;/P&gt;&lt;P&gt;see helpful link:&lt;/P&gt;&lt;P&gt;&lt;A href="http://wannabecybersecurity.blogspot.com/2019/05/configuring-cisco-fmc-network-discovery.html" target="_blank" rel="noopener"&gt;http://wannabecybersecurity.blogspot.com/2019/05/configuring-cisco-fmc-network-discovery.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 13:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918149#M1010449</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-09-03T13:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918479#M1010450</link>
      <description>&lt;P&gt;You can use following guides:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Install and configure firepower ASA service module.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FMC initial configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118595-configure-firesight-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118595-configure-firesight-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Register Device in FMC&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118596-configure-firesight-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118596-configure-firesight-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For monitor mode you can either use monitor-only keyword when redirecting traffic to firepower module or uncheck drop inline option in intrusion policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 20:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3918479#M1010450</guid>
      <dc:creator>Dileep Sivadas Padmini</dc:creator>
      <dc:date>2019-09-03T20:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3920585#M1010451</link>
      <description>&lt;P&gt;Hi Dileep /All.. Is FMC is mandatory required here for managing firepower, Can't policies(webfilter,IPS.etc) be created/configured without FMC.&lt;/P&gt;&lt;P&gt;Also please confirm if any additional license require on FMC for configuring policies.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2019 08:54:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3920585#M1010451</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-07T08:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3920589#M1010452</link>
      <description>&lt;P&gt;You can configure and deploy policies for your ASA Firepower service module using ASDM. ASDM can manage only one module at a time and does not provide any historical reporting or object and policy reuse.&lt;/P&gt;
&lt;P&gt;If you use FMC you get much more fine tuning, visibility and reporting features. You can also manage multiple modules and use common objects and policies. FMC requires its own license.&lt;/P&gt;
&lt;P&gt;Whether you use ASDM or FMC you require a no-cost Control license for each module (mandatory). Depending on which features you want to use you must also purchase IPS, URL Filtering or Malware (AMP) licenses. They are all term subscriptions or licenses and are available for 1-, 3-, or 5-years. You can buy them individually or in combination packages (costs a bit less that way).&lt;/P&gt;</description>
      <pubDate>Sat, 07 Sep 2019 09:40:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3920589#M1010452</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-07T09:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3927548#M1010453</link>
      <description>&lt;P&gt;Hi..Thanks for your suggestion.&lt;/P&gt;&lt;P&gt;I just have configured ASA firepower but after configuring IP add, mask ..etc details. It is throwing some error and putting me into same window and asking to configure again IP add, mask.etc details. Please see below error log. Is is king of bug.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;================================================&lt;/P&gt;&lt;P&gt;System (/usr/local/sf/bin/service_control.sh iptables restart) Failed -- (iptables-restore: line 1 failed)&lt;/P&gt;&lt;P&gt;Printing stack trace:&lt;BR /&gt;called from /usr/lib/perl5/site_perl/5.10.1/Error.pm (150)&lt;BR /&gt;called from /usr/lib/perl5/site_perl/5.10.1/Error.pm (396)&lt;BR /&gt;called from /usr/local/sf/lib/perl/5.10.1/SF/PeerManager/ConfigFiles.pm (785)&lt;BR /&gt;called from /usr/local/sf/lib/perl/5.10.1/SF/PeerManager/ConfigFiles.pm (1110)&lt;/P&gt;&lt;P&gt;====================================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa# sh ver&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.8(1)&lt;BR /&gt;Firepower Extensible Operating System Version 2.2(1.47)&lt;BR /&gt;Device Manager Version 7.8(1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa# sh module sfr details&lt;BR /&gt;Getting details from the Service Module, please wait...&lt;/P&gt;&lt;P&gt;Card Type: FirePOWER Services Software Module&lt;BR /&gt;Model: ASA5545&lt;BR /&gt;Hardware version: N/A&lt;BR /&gt;Serial Number: XXXXX&lt;BR /&gt;Firmware version: N/A&lt;BR /&gt;Software version: 6.2.0-362&lt;BR /&gt;MAC Address Range: 1880.90f8.72a5 to 1880.90f8.72a5&lt;BR /&gt;App. name: ASA FirePOWER&lt;BR /&gt;App. Status: Up&lt;BR /&gt;App. Status Desc: Normal Operation&lt;BR /&gt;App. version: 6.2.0-362&lt;BR /&gt;Data Plane Status: Up&lt;BR /&gt;Console session: Ready&lt;BR /&gt;Status: Up&lt;BR /&gt;DC addr: No DC Configured&lt;BR /&gt;Mgmt IP addr: X.X.X.X&lt;BR /&gt;Mgmt Network mask: 255.255.255.0&lt;BR /&gt;Mgmt Gateway: X.X.X.X&lt;BR /&gt;Mgmt web ports: 443&lt;BR /&gt;Mgmt TLS enabled: true&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 12:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3927548#M1010453</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-20T12:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3927897#M1010454</link>
      <description>&lt;P&gt;The output indicates the module is up/up and an FMC manager is configured. Have you registered the device from within FMC?&lt;/P&gt;</description>
      <pubDate>Sat, 21 Sep 2019 04:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3927897#M1010454</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-21T04:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3928506#M1010455</link>
      <description>&lt;P&gt;Hi Marvin.. i will use ASDM to access firepower module.&lt;/P&gt;&lt;P&gt;Need one more help here to configure firepower module. Management interface of ASA is free so will use it for firepower management. There will be no name and security level under the management interface and will provide firepower module ip from same segment of ASA inside interface. Now gateway address need to be of ASA inside interface or core switch connected to ASA inside. Please confirm on correct gateway need to configure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if we configure manager ip on firepower then we will not able to access it through ASDM? please confirm.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 12:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3928506#M1010455</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-23T12:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3928602#M1010456</link>
      <description>&lt;P&gt;Gateway address should be whatever gateway allows you to reach the rest of your internal network, including the Firepower Management Center. If your core switch is where you route to from the ASA Inside interface and that switch uses SVIs (VLAN interfaces) then you should use that. Just connect the ASA management interface into a switch interface on the same VLAN as the ASA inside interface.&lt;/P&gt;
&lt;P&gt;And yes - when you configure an FMC as the manager that will disable the use of ASDM for Firepower service module management.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 14:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3928602#M1010456</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-23T14:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3931893#M1010457</link>
      <description>&lt;P&gt;Hi.. i have done setting up firepower now and able to see firepower tabs and redirected traffic on ASA towards firepower. I have not yet setup any policies, its showing default traffic allow on firepower. But why i am not able to see anything on firepower reporting graph. is there any thing left to do.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Sep 2019 15:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3931893#M1010457</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-28T15:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3931968#M1010458</link>
      <description>&lt;P&gt;At a minimum you need to assign an Intrusion Policy to your traffic flowing through the Firepower service module. Most basic users assign "Balanced Security and Connectivity" and enable logging (at beginning of connection and to event viewer) for that policy.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2019 02:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3931968#M1010458</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-29T02:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3932037#M1010459</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thanks for update, i have done same but still no data display in ASDM under firepower reporting section.&lt;/P&gt;&lt;P&gt;I had created policy, any any under all section and call IPS and logging as begining of connection.. but still no data displaying. Please suggest.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2019 09:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3932037#M1010459</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-29T09:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3932058#M1010460</link>
      <description>&lt;P&gt;Can you share the class-map, policy map etc. bits of the ASA config that redirect the traffic to the Firepower module?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2019 11:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3932058#M1010460</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-29T11:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3932082#M1010461</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Please see below and suggest.&lt;/P&gt;&lt;P&gt;asa# sh access-list sfr&lt;BR /&gt;access-list sfr; 1 elements; name hash: 0x7b320f74&lt;BR /&gt;access-list sfr line 1 extended permit ip any any (hitcnt=9328926) 0x57cb890e&lt;BR /&gt;asa# sh access-list sfr&lt;BR /&gt;access-list sfr; 1 elements; name hash: 0x7b320f74&lt;BR /&gt;access-list sfr line 1 extended permit ip any any (hitcnt=9344021) 0x57cb890e&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map sfr&lt;BR /&gt;match access-list sfr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect icmp&lt;BR /&gt;inspect pptp&lt;BR /&gt;inspect icmp error&lt;BR /&gt;inspect ip-options&lt;BR /&gt;class global_class&lt;BR /&gt;flow-export event-type all destination X.X.X.X&lt;BR /&gt;class sfr&lt;BR /&gt;sfr fail-open&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa# sh service-policy sfr&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;Service-policy: global_policy&lt;BR /&gt;Class-map: sfr&lt;BR /&gt;SFR: card status Up, mode fail-open&lt;BR /&gt;packet input 9897398, packet output 9897461, drop 0, reset-drop 0&lt;BR /&gt;&lt;BR /&gt;asa# sh service-policy sfr&lt;/P&gt;&lt;P&gt;Global policy:&lt;BR /&gt;Service-policy: global_policy&lt;BR /&gt;Class-map: sfr&lt;BR /&gt;SFR: card status Up, mode fail-open&lt;BR /&gt;packet input 9897868, packet output 9897931, drop 0, reset-drop 0&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2019 13:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3932082#M1010461</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-09-29T13:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3935965#M1010462</link>
      <description>&lt;P&gt;Hi . I have recently setup firesight management center and tried to add firepower in FMC but got error.&lt;/P&gt;&lt;P&gt;Actually Firepower is at location A and FMC resides in location B and both location are connected through sitetosite IPSec VPN. Do i need to put nat-id here.&lt;/P&gt;&lt;P&gt;I am able to ping FMC from firepower.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Oct 2019 10:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3935965#M1010462</guid>
      <dc:creator>Anukalp S</dc:creator>
      <dc:date>2019-10-06T10:21:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with Firepower module</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3936300#M1010463</link>
      <description>&lt;P&gt;You only need nat-id if the address of one or both ends appears as a NATted address to the peer.&lt;/P&gt;
&lt;P&gt;Can you share the exact error that you received?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 10:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-firepower-module/m-p/3936300#M1010463</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-07T10:13:20Z</dc:date>
    </item>
  </channel>
</rss>

