<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Separate subnets are fine in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678846#M1027330</link>
    <description>&lt;P&gt;Separate subnets are fine.&lt;/P&gt;&lt;P&gt;Like you've correctly&amp;nbsp;observed - the FirePOWER module only needs to communicate (IP-wise) with FireSIGHT Management Center.&lt;/P&gt;&lt;P&gt;That path is completely independent of the data plane path through the ASA. The ASA redirects traffic via the service-policy to the FirePOWER module completely internally to the appliance.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2015 03:12:01 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-04-30T03:12:01Z</dc:date>
    <item>
      <title>Can FirePower management interface &amp; ASA-Inside interface be on seperate subnet?</title>
      <link>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678845#M1027329</link>
      <description>&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;Need some clarifications, please.&lt;/P&gt;&lt;P&gt;I have a requirment needed to put FirePower management interface and ASA-Inside interface&amp;nbsp;on a different&amp;nbsp;subnets, does it support?&lt;/P&gt;&lt;P&gt;From what i read so far, most of&amp;nbsp;document&amp;nbsp;suggests to put both interfaces on&amp;nbsp;the same subnet, is there a&amp;nbsp;reason to do that?&lt;/P&gt;&lt;P&gt;I may be wrong but i think FirePower uses management interface to communicate with FireSight for control and comamnd traffic only, the actual data plane traffic is still flowing from ASA-Outside to Inside and vice versa, so as long as there is an ip connectivity between FireSight and FirePower, it should be ok, right? or am i totally wrong, they have to be on the same subnet?&lt;/P&gt;&lt;P&gt;ASA5515-x with FirePower 5.3.1&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:40:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678845#M1027329</guid>
      <dc:creator>TCAM</dc:creator>
      <dc:date>2019-03-12T12:40:22Z</dc:date>
    </item>
    <item>
      <title>Separate subnets are fine</title>
      <link>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678846#M1027330</link>
      <description>&lt;P&gt;Separate subnets are fine.&lt;/P&gt;&lt;P&gt;Like you've correctly&amp;nbsp;observed - the FirePOWER module only needs to communicate (IP-wise) with FireSIGHT Management Center.&lt;/P&gt;&lt;P&gt;That path is completely independent of the data plane path through the ASA. The ASA redirects traffic via the service-policy to the FirePOWER module completely internally to the appliance.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2015 03:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678846#M1027330</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-04-30T03:12:01Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin for taking time</title>
      <link>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678847#M1027331</link>
      <description>&lt;P&gt;Thanks Marvin for taking time to review it.&lt;/P&gt;&lt;P&gt;I tested the setup in lab, yes, it is completely independent and working fine.&lt;/P&gt;</description>
      <pubDate>Fri, 01 May 2015 16:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firepower-management-interface-asa-inside-interface-be-on/m-p/2678847#M1027331</guid>
      <dc:creator>TCAM</dc:creator>
      <dc:date>2015-05-01T16:10:10Z</dc:date>
    </item>
  </channel>
</rss>

