<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Daniel, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firepower-inline-tap-mode/m-p/2909615#M1031702</link>
    <description>Hi Daniel,

Configuring ASA with monitor only would just send a copy of traffic to Firepower and not the actual traffic so that's passive mode. 
It can be configured inline and then use an intrusion policy with "drop when inline" option disabled. You would need to make sure that there is no access rule in access control policy which has action as block so that no other traffic is dropped.

Let me know if it helps.

Thanks,
Yogesh</description>
    <pubDate>Wed, 23 Mar 2016 08:44:24 GMT</pubDate>
    <dc:creator>yogdhanu</dc:creator>
    <dc:date>2016-03-23T08:44:24Z</dc:date>
    <item>
      <title>ASA FirePOWER - Inline Tap Mode</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-inline-tap-mode/m-p/2909614#M1031701</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I would like to understand the configuration of Inline Tap Mode in ASA with FirePOWER.&lt;/P&gt;
&lt;P&gt;To operate in this mode, I need to configure the ASA policy-map to &lt;STRONG&gt;monitor-only&lt;/STRONG&gt; or can &lt;STRONG&gt;keep inline&lt;/STRONG&gt; and create an Intrusion-Policy on FMC with&amp;nbsp;&lt;STRONG&gt;Drop When Inline&lt;/STRONG&gt; option disabled?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What would be the right option?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Daniel Stefani&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-inline-tap-mode/m-p/2909614#M1031701</guid>
      <dc:creator>Daniel Stefani</dc:creator>
      <dc:date>2019-03-12T12:55:57Z</dc:date>
    </item>
    <item>
      <title>Hi Daniel,</title>
      <link>https://community.cisco.com/t5/network-security/asa-firepower-inline-tap-mode/m-p/2909615#M1031702</link>
      <description>Hi Daniel,

Configuring ASA with monitor only would just send a copy of traffic to Firepower and not the actual traffic so that's passive mode. 
It can be configured inline and then use an intrusion policy with "drop when inline" option disabled. You would need to make sure that there is no access rule in access control policy which has action as block so that no other traffic is dropped.

Let me know if it helps.

Thanks,
Yogesh</description>
      <pubDate>Wed, 23 Mar 2016 08:44:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firepower-inline-tap-mode/m-p/2909615#M1031702</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-03-23T08:44:24Z</dc:date>
    </item>
  </channel>
</rss>

