<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do I understand correctly in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891159#M1030135</link>
    <description>&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="0:22"&gt;Do I understand correctly&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="23:26"&gt;that if i use sensor as passive i can&amp;nbsp;&lt;SPAN&gt;discovering my network?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2016 13:00:30 GMT</pubDate>
    <dc:creator>n.avramenko87</dc:creator>
    <dc:date>2016-07-05T13:00:30Z</dc:date>
    <item>
      <title>Testing the device in production.</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891156#M1030132</link>
      <description>&lt;P&gt;Hello friends! I need your help again. How can I tested sensor in production? When I apply&amp;nbsp;&lt;SPAN class="translation-chunk" data-align="0:10"&gt;any&lt;/SPAN&gt;&lt;SPAN class="translation-chunk"&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="12:20"&gt;of politic&lt;/SPAN&gt;&lt;SPAN class="translation-chunk"&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="21:34"&gt;or settings to fire power I have&amp;nbsp;&lt;SPAN class="translation-chunk" data-align="0:20"&gt;&amp;nbsp;a break in&lt;/SPAN&gt;&lt;SPAN class="translation-chunk"&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="21:32"&gt;the network work.&lt;SPAN class="translation-chunk" data-align="0:1"&gt;And&lt;/SPAN&gt;&lt;SPAN class="translation-chunk"&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="2:20"&gt;it bothers me!It is not good tested in production.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What I have:&lt;/P&gt;
&lt;P&gt;1.Internet -- ASA -- FIREPOWER - (Switch - - - MY LAN------)&lt;/P&gt;
&lt;P&gt;I see it as a working version of my lan.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;2.Can I use for testing this&amp;nbsp;&lt;SPAN&gt;scheme:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Internet -- ASA - - (Switch - FIREPOWER - Switch - MY LAN------) Will it work?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891156#M1030132</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2019-03-12T13:03:47Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891157#M1030133</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes, the second scenario is supposed to work fine.&lt;/P&gt;
&lt;P&gt;If you are using firepower module running on ASA,then you can try putting the module in monitor-only and monitor the traffic which is coming to the same.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you have sensor, then you can enable inline set for interfaces and make sure first they are up&lt;/P&gt;
&lt;P&gt;and then you can direct traffic, if in case you encounter the problem enable bypass for the interface so that traffic is bypassed through the sensor.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Note: make sure that interface settings such as duplex speed match the inline sets on the sensor&lt;/P&gt;
&lt;P&gt;and on the sensor set it to auto negotiate.&lt;/P&gt;
&lt;P&gt;Please mark and rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Ankita&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 11:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891157#M1030133</guid>
      <dc:creator>ankojha</dc:creator>
      <dc:date>2016-07-05T11:30:37Z</dc:date>
    </item>
    <item>
      <title>I use only Sensor.</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891158#M1030134</link>
      <description>&lt;P&gt;I use only Sensor.&lt;/P&gt;
&lt;P&gt;Thank you for your answer. At first i need to use sensos for discovering network.And 2 scheme will be work! I try it to testing!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But in production i think it is only firsh scheme can works.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 12:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891158#M1030134</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-05T12:30:33Z</dc:date>
    </item>
    <item>
      <title>Do I understand correctly</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891159#M1030135</link>
      <description>&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="0:22"&gt;Do I understand correctly&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="23:26"&gt;that if i use sensor as passive i can&amp;nbsp;&lt;SPAN&gt;discovering my network?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 13:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891159#M1030135</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-05T13:00:30Z</dc:date>
    </item>
    <item>
      <title>Hello Team,</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891160#M1030136</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;Either you can set your ASA firepower &amp;nbsp;in monitor only or inline mode.&lt;/P&gt;
&lt;P&gt;When its in inline mode, it will inspect the traffic that is redirects from ASA&amp;nbsp;&amp;nbsp;to Firepower and Firepower will take the actions based on the policies that you mentioned.&lt;/P&gt;
&lt;P&gt;If you dont need then you can just keep the Firepower in monitor only mode so that it will send just the copy of traffic to Firepower and it wont perform any inspection.&lt;/P&gt;
&lt;P&gt;It would be good if you refer the following deployment scenario guides to understand more about how to setup and also refer the second link for initial installation and traffic redirection after installation.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/ips-sensor-software-version-71/113690-ips-config-mod-00.html &amp;nbsp; (this is applicable for Firepower setup also )&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html&lt;/P&gt;
&lt;P&gt;Rate and mark correct , if the post helps you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 14:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891160#M1030136</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-05T14:40:33Z</dc:date>
    </item>
    <item>
      <title>OK! Thank you! I have one</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891161#M1030137</link>
      <description>&lt;P&gt;OK! Thank you! I have 2&amp;nbsp;questions!&lt;/P&gt;
&lt;P&gt;1.One man said me that if we want to use &amp;nbsp;FirePower &amp;nbsp;we need router :&lt;/P&gt;
&lt;P&gt;Internet -- Router -- FirePower -- ASA -- LAN&lt;/P&gt;
&lt;P&gt;In my lan ASA used as a router too.Can &amp;nbsp;I used FirePower without Router:&lt;/P&gt;
&lt;P&gt;Internet -- ASA -- FirePower -- LAN&lt;/P&gt;
&lt;P&gt;2. I try to configure sensor. I want to see all information about my lan (host computers ports applications)&lt;/P&gt;
&lt;P&gt;- I configured &amp;nbsp;access control policy - network discovery only&lt;/P&gt;
&lt;P&gt;- system find only hosts in my lan&lt;/P&gt;
&lt;P&gt;I &lt;SPAN&gt;read&lt;/SPAN&gt; manuals &amp;nbsp;and&amp;nbsp;&lt;SPAN&gt;if I understand correctly that for "application seen" I need to configure &amp;nbsp;Active Scanning? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And I see that firesigh has application detectors, how can I use it?&amp;nbsp;С&lt;SPAN&gt;ould there be best practice for using sensor?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 07:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891161#M1030137</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-06T07:02:19Z</dc:date>
    </item>
    <item>
      <title>Hello! And still would like</title>
      <link>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891162#M1030138</link>
      <description>&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="0:1"&gt;Hello! And&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="2:10"&gt;still&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="11:28"&gt;would like to clarify&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="29:39"&gt;information. I have the same lan that on the scheme. Will it work with FirePower? Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2016 08:16:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/testing-the-device-in-production/m-p/2891162#M1030138</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-12T08:16:18Z</dc:date>
    </item>
  </channel>
</rss>

