<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Replace ASA firewall with FTD design. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replace-asa-firewall-with-ftd-design/m-p/3767806#M1028817</link>
    <description>&lt;P&gt;Currently, the firewall is setup with 3 interfaces (internet, inside and dmz). The DMZ and Inside using subinterfaces on a port channel to respective vrfs for dmz and inside network. Now this will be replace with FTD next year and we desire to use FTD for routed mode but also leverage the NGFW and NGIPs features together.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my research it seems FTD has to be in TRANSPARENT mode only to use NGIPs features or Inline Sets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to use the routed mode and&amp;nbsp; inline set without having a buy additional hardware with the existing design of 3 zones (inside, dmz and inet)?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:35:54 GMT</pubDate>
    <dc:creator>michael ezenogha</dc:creator>
    <dc:date>2020-02-21T16:35:54Z</dc:date>
    <item>
      <title>Replace ASA firewall with FTD design.</title>
      <link>https://community.cisco.com/t5/network-security/replace-asa-firewall-with-ftd-design/m-p/3767806#M1028817</link>
      <description>&lt;P&gt;Currently, the firewall is setup with 3 interfaces (internet, inside and dmz). The DMZ and Inside using subinterfaces on a port channel to respective vrfs for dmz and inside network. Now this will be replace with FTD next year and we desire to use FTD for routed mode but also leverage the NGFW and NGIPs features together.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From my research it seems FTD has to be in TRANSPARENT mode only to use NGIPs features or Inline Sets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to use the routed mode and&amp;nbsp; inline set without having a buy additional hardware with the existing design of 3 zones (inside, dmz and inet)?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-asa-firewall-with-ftd-design/m-p/3767806#M1028817</guid>
      <dc:creator>michael ezenogha</dc:creator>
      <dc:date>2020-02-21T16:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Replace ASA firewall with FTD design.</title>
      <link>https://community.cisco.com/t5/network-security/replace-asa-firewall-with-ftd-design/m-p/3767813#M1028818</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;FTD routed mode supports&amp;nbsp;Full LINA-engine and Snort-engine checks. You can configure inline set in routed mode as well.&lt;/P&gt;
&lt;P&gt;If it is in transparent or routed mode, for IPS inspection you need to buy threat license.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-12-10 19_29_29-Configure FTD Interfaces in Inline-Pair Mode - Cisco.jpg" style="width: 955px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/25606i18B2125FEE6D7B35/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-12-10 19_29_29-Configure FTD Interfaces in Inline-Pair Mode - Cisco.jpg" alt="2018-12-10 19_29_29-Configure FTD Interfaces in Inline-Pair Mode - Cisco.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Abheesh&lt;BR /&gt;PS: Please don't forget to rate and select as validated answer if this answered your question&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 11:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-asa-firewall-with-ftd-design/m-p/3767813#M1028818</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-12-21T11:12:02Z</dc:date>
    </item>
  </channel>
</rss>

