<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Managing the ASA and in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786930#M1032766</link>
    <description>&lt;P&gt;Managing the ASA and SourceFire is usually done by the dedicated management ports. &amp;nbsp;As such, you can configure the management port with an IP address belonging to any subnet you choose. &amp;nbsp;Note that SourceFire needs to be able to download information from the Internet.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2016 18:38:43 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-01-04T18:38:43Z</dc:date>
    <item>
      <title>Sourcefire POC</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786927#M1032760</link>
      <description>&lt;P&gt;Hello guys i am doing sourcefire POC can anyone please guide me on the following&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have 5585 with source fire hardware module&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below is the topology after putting ASA 5585 {as of now there is no asa In between}&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/pimgpsh_fullsize_distr.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the configuration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Core-1:&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;description Link to s-rl-ns-dat-1 &lt;BR /&gt;ip address 10.200.0.1 255.255.255.252&lt;BR /&gt;ip flow egress&lt;BR /&gt;ip policy route-map _CO_INET&lt;BR /&gt;ip ospf network point-to-point&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;CORE-2:&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;description Link to s-rl-ns-dat-2 &lt;BR /&gt;ip address 10.200.0.69 255.255.255.252&lt;BR /&gt;ip policy route-map _CO_INET&lt;BR /&gt;ip ospf network point-to-point&lt;BR /&gt;wrr-queue cos-map 2 2 3 6 7 &lt;BR /&gt; wrr-queue cos-map 3 1 4 &lt;BR /&gt; snmp ifindex persist&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;DAT-1:&lt;BR /&gt;interface GigabitEthernet1/1/7&lt;BR /&gt;description * Link to s-rl-ns-cor-1 &lt;BR /&gt;no switchport&lt;BR /&gt;ip address 10.200.0.2 255.255.255.252&lt;BR /&gt;ip ospf network point-to-point&lt;BR /&gt;ip ospf cost 5&lt;BR /&gt;mls qos trust dscp&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;DAT-2:&lt;BR /&gt;interface GigabitEthernet2/1/7&lt;BR /&gt;description * Link to s-rl-ns-cor-2&lt;BR /&gt;no switchport&lt;BR /&gt;ip address 10.200.0.70 255.255.255.252&lt;BR /&gt;ip policy route-map _CO_INET&lt;BR /&gt;ip ospf network point-to-point&lt;BR /&gt;mls qos trust dscp&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please give me Idea how can i configure ASA 5585 in transparent mode&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786927#M1032760</guid>
      <dc:creator>Nishad Dadhaniya</dc:creator>
      <dc:date>2019-03-12T12:51:30Z</dc:date>
    </item>
    <item>
      <title>Put the ASA in transparent</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786928#M1032762</link>
      <description>&lt;P&gt;Put the ASA in transparent mode first:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/97853-Transparent-firewall.html"&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/97853-Transparent-firewall.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Then configure SourceFire as normal.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 13:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786928#M1032762</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-04T13:33:07Z</dc:date>
    </item>
    <item>
      <title>That i understood , I have</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786929#M1032764</link>
      <description>&lt;P&gt;That i understood , I have couple of doubts&lt;/P&gt;
&lt;P&gt;1) we need to require BVI ?&amp;nbsp;&lt;BR /&gt;2) &lt;SPAN&gt;The management IP address must be on the same subnet as the connected network. ? as we have /30 its not possible&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;what i am thinking is dis1 is inside 1 and dis2 is inside2 , core1 is outside1 and core2 is outside2&lt;/P&gt;
&lt;P&gt;and management IP which also is in same subnet as firepower hdw module but as management subnet is different then connected data network how can we achieve this ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 18:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786929#M1032764</guid>
      <dc:creator>Nishad Dadhaniya</dc:creator>
      <dc:date>2016-01-04T18:18:26Z</dc:date>
    </item>
    <item>
      <title>Managing the ASA and</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786930#M1032766</link>
      <description>&lt;P&gt;Managing the ASA and SourceFire is usually done by the dedicated management ports. &amp;nbsp;As such, you can configure the management port with an IP address belonging to any subnet you choose. &amp;nbsp;Note that SourceFire needs to be able to download information from the Internet.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 18:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-poc/m-p/2786930#M1032766</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-04T18:38:43Z</dc:date>
    </item>
  </channel>
</rss>

