<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FirePower on Multicontext ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782201#M1011288</link>
    <description>&lt;P&gt;I'm looking to activate the FirePower services on a 5555X ASA which run in HA and multi-context mode (3 contexts). I'm used to manage FirePower devices and &lt;SPAN&gt;multi&lt;/SPAN&gt;&lt;SPAN&gt;-context ASAs but&amp;nbsp;never tried both together up to this point.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any license requirements for multi-context or do we only need standard FirePower licenses? (1&amp;nbsp;L-ASA5555-TAMC per device?) FirePower boxes seem to allow for 10 contexts without additional licenses but I can't find the information for the FirePower module running on ASA boxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will each Firepower module consume a single license in the Management center or does each context count as a managed device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I have a couple technical question&amp;nbsp;&lt;SPAN&gt;- I guess I'll find out in the lab tests but I'm a bit curious;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My understanding is that the FP module can only be activated/deactivated for all contexts but there's only a need for FP in 2 of our 3 ASA contexts. Are the contexts shown as separate devices in the management center? If so I guess it would be simple to just apply a policy to allow all the traffic for one of the context.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 14:13:59 GMT</pubDate>
    <dc:creator>Cedrik</dc:creator>
    <dc:date>2019-03-12T14:13:59Z</dc:date>
    <item>
      <title>FirePower on Multicontext ASA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782201#M1011288</link>
      <description>&lt;P&gt;I'm looking to activate the FirePower services on a 5555X ASA which run in HA and multi-context mode (3 contexts). I'm used to manage FirePower devices and &lt;SPAN&gt;multi&lt;/SPAN&gt;&lt;SPAN&gt;-context ASAs but&amp;nbsp;never tried both together up to this point.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any license requirements for multi-context or do we only need standard FirePower licenses? (1&amp;nbsp;L-ASA5555-TAMC per device?) FirePower boxes seem to allow for 10 contexts without additional licenses but I can't find the information for the FirePower module running on ASA boxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will each Firepower module consume a single license in the Management center or does each context count as a managed device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I have a couple technical question&amp;nbsp;&lt;SPAN&gt;- I guess I'll find out in the lab tests but I'm a bit curious;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;My understanding is that the FP module can only be activated/deactivated for all contexts but there's only a need for FP in 2 of our 3 ASA contexts. Are the contexts shown as separate devices in the management center? If so I guess it would be simple to just apply a policy to allow all the traffic for one of the context.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:13:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782201#M1011288</guid>
      <dc:creator>Cedrik</dc:creator>
      <dc:date>2019-03-12T14:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower on Multicontext ASA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782289#M1011289</link>
      <description>&lt;P&gt;I'm looking to activate the FirePower services on a 5555X ASA which run in HA and multi-context mode (3 contexts). I'm used to manage FirePower devices and &lt;SPAN&gt;multi&lt;/SPAN&gt;&lt;SPAN&gt;-context ASAs but&amp;nbsp;never tried both together up to this point.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;as long as you have worked on ASA with SFR its a same thing nothing to worry.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any license requirements for multi-context or do we only need standard FirePower licenses? (1&amp;nbsp;L-ASA5555-TAMC per device?) FirePower boxes seem to allow for 10 contexts without additional licenses but I can't find the information for the FirePower module running on ASA boxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;if SFR which i am sure you are on ASA software with SFR which will be a traditional licinece. and to answer your question on (1&amp;nbsp;L-ASA5555-TAMC per device?) yes. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will each Firepower module consume a single license in the Management center or does each context count as a managed device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;single license per box of ASA.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My understanding is that the FP module can only be activated/deactivated for all contexts but there's only a need for FP in 2 of our 3 ASA contexts. Are the contexts shown as separate devices in the management center? If so I guess it would be simple to just apply a policy to allow all the traffic for one of the context.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;in my production network we are running multi context but with only one context. i remember when i added the sfr in FMC. it just pick up itself everything and i have to deivce the interfaces from the object managemt tab&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jan 2019 17:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782289#M1011289</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-01-17T17:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower on Multicontext ASA</title>
      <link>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782664#M1011290</link>
      <description>&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;correctly replied, I would add that the Firepower service module really isn't aware of the multiple contexts. It is a single managed device (per physical ASA - so two devices if you have an HA pair of ASAs) in FMC, it uses one license and it has a single policy set applied to it. So your Firepower policy set needs to account for any and all contexts that are sending traffic to it via their respective service-policy setting(s) in the individual ASA contexts.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 06:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-on-multicontext-asa/m-p/3782664#M1011290</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-01-18T06:00:58Z</dc:date>
    </item>
  </channel>
</rss>

