<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic For the IPS feature on in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962707#M1018048</link>
    <description>&lt;P&gt;For the IPS feature on Sourcefire appliances and ASA FirePOWER modules, Cisco does not &lt;STRONG&gt;currently&lt;/STRONG&gt; enforce by technical means the ability to continue to download Snort Rule Updates (SRU) and Vulnerability Database (VDB) into your FMC or ASDM and then apply them to any registered devices having the non-expiring Protect + Control licenses.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;i.e., They do not check for presence of a valid IPS subscription or support contract like they used to with the classic Cisco IPS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;However, the terms of use of the subscription agreement require you to have a current subscription to continue these updates.&lt;/P&gt;
&lt;P&gt;In contrast, policy elements using the URL filtering and AMP licenses will stop working once those licenses expire.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Dec 2016 04:33:30 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-12-21T04:33:30Z</dc:date>
    <item>
      <title>Questions regarding Cisco ASA with Firepower + Firepower Management Center</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962701#M1018042</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I still don´t fully understand the licensing in relation to Cisco ASA Firepower Licensing. I already asked a question regarding the FMC here: &lt;A href="https://supportforums.cisco.com/discussion/13086371/firesight-license-60-not-needed" target="_blank"&gt;https://supportforums.cisco.com/discussion/13086371/firesight-license-60-not-needed&lt;/A&gt;. I learned, that for Firesight, we still need a license for Support. In general I read the new order guide. (&lt;A href="http://www.cisco.com/c/en/us/products/collateral/security/firepower-8000-series-appliances/guide-c07-737902.html?cachemode=refresh" target="_blank"&gt;http://www.cisco.com/c/en/us/products/collateral/security/firepower-8000-series-appliances/guide-c07-737902.html?cachemode=refresh&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Lets assume, we want to use 2x Cisco ASA5525x as a Failover pair with Failover Firepower Services Module. The Firesight Management Center is standalone, installed as a virtual machine in vmware. The&amp;nbsp;complete system is up and running, everything is prepared, only the Control Licenses are installed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now I want to sum up my question&amp;nbsp;with an example. My question is, what licenses are really&amp;nbsp;necessary in order to be able/allowed to make Software Updates/Upgrades&amp;nbsp;for Cisco ASA Firepower Software and Firesight Management Center Software.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Are these licenses sufficient?&lt;/P&gt;
&lt;P&gt;- 2x Cicso ASA5525 Firepower IPS 3YR L-ASA5525-TA-3Y&lt;/P&gt;
&lt;P&gt;- Cisco Service SW App Supp + Upgr (SAU)&amp;nbsp;&lt;SPAN&gt;FS-VMW-2-SW-K9&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What for reasons do I need to order L-ASA5525-TA-3Y? Is it necessary,&amp;nbsp;to&amp;nbsp;1.) get product updates/upgrades and 2.) to be able to download IPS patterns? For this is a question, because u&lt;/SPAN&gt;&lt;SPAN&gt;ntil now, I didn´t Install any license but the control license, but as you can see, I was already able to activate protection and control&amp;nbsp;for both&amp;nbsp;ASA Sensors. What would be, if I don´t order and install&amp;nbsp;L-ASA5525-TA-3Y, what Features would not be accessible/useable?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I just want to clarify all this questions... Hopefully some of you guys already went through this jungle&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sebastian&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:58:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962701#M1018042</guid>
      <dc:creator>roesch4alc</dc:creator>
      <dc:date>2020-02-21T13:58:49Z</dc:date>
    </item>
    <item>
      <title>Hello Sebastian. My answers</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962702#M1018043</link>
      <description>&lt;P&gt;Hello Sebastian. My answers below:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;I learned, that for Firesight, we still need a license for Support. In general I read the new order guide. &lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NS&lt;/STRONG&gt;&lt;/SPAN&gt;: Yes, even though not enforced anymore the license should still be purchased to be compliant&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Are these licenses sufficient?&lt;BR /&gt;- 2x Cicso ASA5525 Firepower IPS 3YR L-ASA5525-TA-3Y&lt;BR /&gt;- Cisco Service SW App Supp + Upgr (SAU)&amp;nbsp;&lt;SPAN&gt;FS-VMW-2-SW-K9&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NS&lt;/STRONG&gt;&lt;/SPAN&gt;: Those licenses will give you Layer 7 Firewall and IPS for the ASA (See below) and Software + Support (TAC) for the virtual FireSIGHT/Defense Center/Firepower Management Center.&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;What for reasons do I need to order L-ASA5525-TA-3Y?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NS&lt;/STRONG&gt;&lt;/SPAN&gt;: This license is a 3 year subscription for ASA model 5525 that enables the IPS (Snort) capabilities of Sourcefire. This license is required if you want to receive IPS signature updates and to be able to configure IPS policies inside FMC&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;&lt;SPAN&gt;Is it necessary,&amp;nbsp;to&amp;nbsp;1.) get product updates/upgrades and 2.) to be able to download IPS patterns?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NS&lt;/STRONG&gt;&lt;/SPAN&gt;: Yes, it is necessary for IPS signature updates.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;For this is a question, because u&lt;/SPAN&gt;&lt;SPAN&gt;ntil now, I didn´t Install any license but the control license, but as you can see, I was already able to activate protection and control&amp;nbsp;for both&amp;nbsp;ASA Sensors. What would be, if I don´t order and install&amp;nbsp;L-ASA5525-TA-3Y, what Features would not be accessible/useable?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;NS&lt;/STRONG&gt;&lt;/SPAN&gt;: That is correct, every ASA (If purchased with the base FirePOWER Bundle) will come by default with the Control and Protect license which is essentially the L7 Firewall. The rest of the features (AMP, IPS and URL Filtering) are an additional subscription.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;I hope this helps!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 02:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962702#M1018043</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-19T02:45:37Z</dc:date>
    </item>
    <item>
      <title>Hi NS,</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962703#M1018044</link>
      <description>&lt;P&gt;Hi NS,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks for your detailed answer, I appreciate it. Just one more question: With the&amp;nbsp;L-ASA5525-TA-3Y License, does it behave the same way like Firesight license, that I am not forced to install the license?&lt;/P&gt;
&lt;P&gt;I learned this license is a RTU (Right to use) license. So&amp;nbsp;I only get a license confirmation, but no licensefile to download or install into FMC.&amp;nbsp;So I could force the&amp;nbsp;FMC system to download&amp;nbsp;this IPS&amp;nbsp;Patterns, even this is not legal.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I think, this whole topic could be&amp;nbsp;explained more better in the licensing guide, currently I am not able to understand it without additional questions. Verfy confusing for me.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Have a nice day,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Sebastian&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 09:40:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962703#M1018044</guid>
      <dc:creator>roesch4alc</dc:creator>
      <dc:date>2016-12-19T09:40:36Z</dc:date>
    </item>
    <item>
      <title>Hi Sebastian-</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962704#M1018045</link>
      <description>&lt;P&gt;Hi Sebastian-&lt;/P&gt;
&lt;P&gt;I hear your pain as licensing has always been a major pain when dealing with not only Cisco but just about any other vendor out there &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;To answer your question: The&amp;nbsp;&lt;SPAN&gt;L-ASA5525-TA-3Y is definitely NOT a RTU type license. This one, along with URL Filtering and AMP are a must if you want to use those features. If the license is not present then those features will not work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 17:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962704#M1018045</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-19T17:58:34Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962705#M1018046</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I cannot really confirm, that it is the same with the other vendors...&amp;nbsp;I have different experiences&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;But now, after your answer:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;To answer your question: The&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;L-ASA5525-TA-3Y is definitely NOT a RTU type license. This one, along with URL Filtering and AMP are a must if you want to use those features. If the license is not present then &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;those features will not work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;, it is starting to become more confusing for me!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is because, I got this answer from a Cisco TAC engineer!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Quote:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #1f497d;"&gt;I clarified this from my end, for you to enable this, you will require a protect and control license for you to be allowed for your software download (for IPS patterns etc).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #1f497d;"&gt;This IPS RTU license is not really a feature for you to enable on your end.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: 'Arial',sans-serif; color: #1f497d;"&gt;For your reference here’s how Sourcefire license work&lt;/SPAN&gt;&lt;SPAN style="font-family: 'Arial',sans-serif;"&gt; &lt;SPAN style="color: #1f497d;"&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118396-technote-firesight-00.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118396-technote-firesight-00.html&lt;/A&gt; as we don’t have a proper documentation for the IPS licenses.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;So, what´s right now? Two people two statements... That´s not very easy ;(&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Sebastian&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 14:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962705#M1018046</guid>
      <dc:creator>roesch4alc</dc:creator>
      <dc:date>2016-12-20T14:35:07Z</dc:date>
    </item>
    <item>
      <title>Furthermore, let me add the</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962706#M1018047</link>
      <description>&lt;P&gt;Furthermore, let me add the fact, that there is no&amp;nbsp;SKU download available.&amp;nbsp;The license, I could download&amp;nbsp;after we ordered it and received the edelivery mail, is only a license EULA, no SKU or license file.... So very confusing for me.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 15:58:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962706#M1018047</guid>
      <dc:creator>roesch4alc</dc:creator>
      <dc:date>2016-12-20T15:58:01Z</dc:date>
    </item>
    <item>
      <title>For the IPS feature on</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962707#M1018048</link>
      <description>&lt;P&gt;For the IPS feature on Sourcefire appliances and ASA FirePOWER modules, Cisco does not &lt;STRONG&gt;currently&lt;/STRONG&gt; enforce by technical means the ability to continue to download Snort Rule Updates (SRU) and Vulnerability Database (VDB) into your FMC or ASDM and then apply them to any registered devices having the non-expiring Protect + Control licenses.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;i.e., They do not check for presence of a valid IPS subscription or support contract like they used to with the classic Cisco IPS.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;However, the terms of use of the subscription agreement require you to have a current subscription to continue these updates.&lt;/P&gt;
&lt;P&gt;In contrast, policy elements using the URL filtering and AMP licenses will stop working once those licenses expire.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 04:33:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962707#M1018048</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-12-21T04:33:30Z</dc:date>
    </item>
    <item>
      <title>Marvin, I stand corrected!</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962708#M1018049</link>
      <description>&lt;P&gt;Marvin, I stand corrected! Thank you for chiming in and correcting me as I think I was an auto-pilot and referencing knowledge from legacy Cisco IPS &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; Upon reviewing my Sourcefire notes I realized my mistake. Endorsement for you sir!&lt;/P&gt;
&lt;P&gt;Happy holidays!&lt;/P&gt;
&lt;P&gt;Neno&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2016 18:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/2962708#M1018049</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2016-12-21T18:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Questions regarding Cisco ASA with Firepower + Firepower Managemen</title>
      <link>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/5340141#M1123220</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I want to migrate vFMC to FMC Appliance HA,when migrate to FMC Appliance it is have downtime or not?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Oct 2025 14:12:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/questions-regarding-cisco-asa-with-firepower-firepower/m-p/5340141#M1123220</guid>
      <dc:creator>leonardo-panbasten</dc:creator>
      <dc:date>2025-10-20T14:12:34Z</dc:date>
    </item>
  </channel>
</rss>

