<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for your reply! I was in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897439#M1031296</link>
    <description>&lt;P&gt;Thanks for your reply! I was in doubt because there is nothing mentioned on active/active failover in the guides for firesight &amp;gt;.&amp;lt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2016 12:38:50 GMT</pubDate>
    <dc:creator>ictbeheer01</dc:creator>
    <dc:date>2016-04-08T12:38:50Z</dc:date>
    <item>
      <title>ASA 5516-x With Firepower services and active/active failover</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897437#M1031283</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have two ASA 5516-X setup in an active/active failover. I have also installed and succesfully bootstrapped the firesight management center with the two sfr modules added and licensed.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And, at this moment I am reading through the firesight management guide, and to my full suprise there is no information in it whatsoever on active/active failover in combination with sourcefire. There is a full chapter dedicated to active/standby failover, though.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;guide here: &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601.html" target="_blank"&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My question is: is there anyone that has an active/active setup running with sourcefire modules and working correctly? and if yes, could you link me to some useful information on setting this up with the sourcefire modules? Or, is his an unsupported setup and should I go on and revert to active/passive failover?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks and regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sjoerd&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897437#M1031283</guid>
      <dc:creator>ictbeheer01</dc:creator>
      <dc:date>2019-03-12T12:58:07Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897438#M1031290</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So from firesight point of view , it doesn't know about the failover. Firesight would still treat both the modules as individual devices. Though same policies can be applied to both of them , keeping them in same config.&lt;/P&gt;
&lt;P&gt;So you can use either active /active or active/passive (ASA) and don't really need to do anything special on firesight.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 12:17:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897438#M1031290</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-04-08T12:17:47Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply! I was</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897439#M1031296</link>
      <description>&lt;P&gt;Thanks for your reply! I was in doubt because there is nothing mentioned on active/active failover in the guides for firesight &amp;gt;.&amp;lt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 12:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897439#M1031296</guid>
      <dc:creator>ictbeheer01</dc:creator>
      <dc:date>2016-04-08T12:38:50Z</dc:date>
    </item>
    <item>
      <title>I just did a deployment this</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897440#M1031301</link>
      <description>&lt;P&gt;I just did a deployment this week with ASA 5555-X multiple context mode firewalls in Active-Active failover.&lt;/P&gt;
&lt;P&gt;Each physical ASA has its own FirePOWER module and those modules are managed by FirePOWER manager. I am using a single policy deployed to both modules. It's working fine and reporting on traffic from both contexts.&lt;/P&gt;
&lt;P&gt;It's kind of nice that as a side benefit of the standard health policy is that you will see an alert highlighted on your manager that the data plane interface is not receiving traffic in the event that all contexts are active on a single ASA (vs. the normal operating mode of having at least one context active on each ASA).&lt;/P&gt;
&lt;P&gt;You can't easily make distinct policies for the different contexts. Another thread suggested using zones to accomplish that; but that may make an already complex setup even more so.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 15:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897440#M1031301</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-08T15:56:19Z</dc:date>
    </item>
    <item>
      <title>Hello Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897441#M1031306</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there any news in version 6.2? I ask because in the coming days I will migrate 2 ASA5585-SSP-IPS40 in HA, that have 2 Virtual Sensor: vs0 associated with the context x and vs1 associated with the context y, for 2 ASA-SSP-SFR40-K9=.&lt;/P&gt;
&lt;P&gt;Will I have to apply the same SFR policies for the 2&amp;nbsp;contexts?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Tks;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ronaldo&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 19:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897441#M1031306</guid>
      <dc:creator>Ronaldo da Silva</dc:creator>
      <dc:date>2017-04-10T19:13:53Z</dc:date>
    </item>
    <item>
      <title>@Ronaldo da Silva  ,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897442#M1031310</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/ronaldotecnologia"&gt;ronaldotecnologia&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;A given sfr module only has a single policy set (1 each access control + intrusion + file etc.). That single set applies to all contexts in a muilti-context mode ASA for which you are inspecting traffic. As of 6.2, you cannot differentiate sfr policies among contexts.&lt;/P&gt;
&lt;P&gt;Even when Cisco introduces multiple context in a later release, it will be for the FTD image which will never be supported on the 5585-X. that is because the 5585-X with FirePOWER module has recently been announced as end of sales.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 02:16:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897442#M1031310</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-11T02:16:25Z</dc:date>
    </item>
    <item>
      <title>Thank you Marvin!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897443#M1031314</link>
      <description>&lt;P&gt;Thank you Marvin!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 02:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897443#M1031314</guid>
      <dc:creator>Ronaldo da Silva</dc:creator>
      <dc:date>2017-04-11T02:25:01Z</dc:date>
    </item>
    <item>
      <title>Finally, what is the command</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897444#M1031316</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Arial','sans-serif'; color: black;"&gt;Finally, what is the command to allocate the SFR module to the context: &lt;BR /&gt; &lt;BR /&gt; (Config) # context x &lt;BR /&gt; (Config-ctx) # ???&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 02:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897444#M1031316</guid>
      <dc:creator>Ronaldo da Silva</dc:creator>
      <dc:date>2017-04-11T02:29:30Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897445#M1031320</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;You don't need to allocate the module resource in the system context setup. You simply call it out in the class map etc. of the individual context(s).&lt;/P&gt;
&lt;P&gt;Something like this suffices for a basic setup:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;access-list sfr extended permit ip any4 any4&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;class-map sfr_class&lt;BR /&gt; match access-list sfr&lt;BR /&gt;!&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class sfr_class&lt;BR /&gt;  sfr fail-open&lt;/PRE&gt;</description>
      <pubDate>Tue, 11 Apr 2017 02:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897445#M1031320</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-11T02:55:07Z</dc:date>
    </item>
    <item>
      <title>Perfect Marvin. Now I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897446#M1031322</link>
      <description>&lt;P&gt;Perfect Marvin. Now I understood why I searched so much and did not find it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 02:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897446#M1031322</guid>
      <dc:creator>Ronaldo da Silva</dc:creator>
      <dc:date>2017-04-11T02:55:08Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897447#M1031325</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;I received the 2 modules: ASA-SSP-SFR40-K9 = and inside their box, came the PAK: ASA5585-40CTRL-LIC.&lt;/P&gt;
&lt;P&gt;The problem is that the numbers are the same. And when generating the license, released only the quantity: 1.&lt;/P&gt;
&lt;P&gt;How can I add / manage the 2 modules in FMC?&lt;/P&gt;
&lt;P&gt;Tks;&lt;/P&gt;
&lt;P&gt;Ronaldo&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 21:53:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897447#M1031325</guid>
      <dc:creator>Ronaldo da Silva</dc:creator>
      <dc:date>2017-04-17T21:53:03Z</dc:date>
    </item>
    <item>
      <title>The order may have</title>
      <link>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897448#M1031330</link>
      <description>&lt;P&gt;The order may have incorrectly specified only one Control license. Two modules requires two licenses.&lt;/P&gt;
&lt;P&gt;You need to have your reseller order another "ASA5585-40CTRL-LIC"&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 02:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5516-x-with-firepower-services-and-active-active-failover/m-p/2897448#M1031330</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-18T02:43:36Z</dc:date>
    </item>
  </channel>
</rss>

