<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5512 Active/Standby with Firepower services in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662728#M103712</link>
    <description>&lt;P&gt;I have two ASA5512X firewalls in Active/Standby mode.&lt;/P&gt;&lt;P&gt;We want now to enable FirePOWER subscription- &lt;EM&gt;TAMC - IPS and Apps Updates plus URL Filtering and AMP Subscription&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;My customer does not want to buy the subscription for the standby firewall.&lt;/P&gt;&lt;P&gt;He needs the standby firewall to do only firewalling, routing and VPN in the event of a failure.&lt;/P&gt;&lt;P&gt;Is it technically possible?&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2015 22:45:54 GMT</pubDate>
    <dc:creator>Michalis Michael</dc:creator>
    <dc:date>2015-03-18T22:45:54Z</dc:date>
    <item>
      <title>ASA5512 Active/Standby with Firepower services</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662728#M103712</link>
      <description>&lt;P&gt;I have two ASA5512X firewalls in Active/Standby mode.&lt;/P&gt;&lt;P&gt;We want now to enable FirePOWER subscription- &lt;EM&gt;TAMC - IPS and Apps Updates plus URL Filtering and AMP Subscription&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;My customer does not want to buy the subscription for the standby firewall.&lt;/P&gt;&lt;P&gt;He needs the standby firewall to do only firewalling, routing and VPN in the event of a failure.&lt;/P&gt;&lt;P&gt;Is it technically possible?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2015 22:45:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662728#M103712</guid>
      <dc:creator>Michalis Michael</dc:creator>
      <dc:date>2015-03-18T22:45:54Z</dc:date>
    </item>
    <item>
      <title>technically it would work.</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662729#M103713</link>
      <description>&lt;P&gt;technically it would work. The service policy would still direct the traffic through the FirePOWER module that's unlicensed (The base FirePOWER software would have to be installed but without any license or policies from FMC).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 01:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662729#M103713</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-03-24T01:44:10Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin for your</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662730#M103714</link>
      <description>&lt;P&gt;Thanks Marvin for your response.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 06:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662730#M103714</guid>
      <dc:creator>Michalis Michael</dc:creator>
      <dc:date>2015-03-24T06:20:00Z</dc:date>
    </item>
    <item>
      <title>You're welcome. Please mark</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662731#M103715</link>
      <description>&lt;P&gt;You're welcome. Please mark your question as answered if it has been.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 12:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662731#M103715</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-03-24T12:10:03Z</dc:date>
    </item>
    <item>
      <title>Hello Marvin,I'm exactly in</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662732#M103716</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;&lt;P&gt;I'm exactly in same situation : buy a license for a standby firewall seems pretty useless (in my case).&lt;/P&gt;&lt;P&gt;You said that technically it will work, but is this asymmetric configuration officially supported ?&lt;/P&gt;&lt;P&gt;Is that possible that TAC refuse to troubleshoot a potential issue in this configuration ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 12:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662732#M103716</guid>
      <dc:creator>Marc Rousseau</dc:creator>
      <dc:date>2015-06-04T12:11:27Z</dc:date>
    </item>
    <item>
      <title>It's not an issue of TAC</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662733#M103717</link>
      <description>&lt;P&gt;It's not an issue of TAC support. From the point of view of the FireSIGHT Management Center, you have two separate managed ASA's, each with a different set of policies applied.&lt;/P&gt;&lt;P&gt;The problem is that your desired security level - with intrusion, URL and potentially file (AMP) policies - cannot be applied to a module without the prerequisite license. So you need to make two sets of policies - one for the fully licensed module and one for the partially licensed module. Depending on what licenses you have on the latter, your security protection may suffer during a failover scenario until you've restored the primary unit to operation.&lt;/P&gt;&lt;P&gt;Operationally you could go in and "unlicense" the failed module and apply that license to the operational one and then reapply the more secure policy set. That's a lot more headache and opportunity for human error than is advisable for most customers though.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 13:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662733#M103717</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-06-04T13:15:24Z</dc:date>
    </item>
    <item>
      <title>Thank you for your answer</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662734#M103718</link>
      <description>&lt;P&gt;Thank you for your answer Marvin !&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2015 15:41:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662734#M103718</guid>
      <dc:creator>Marc Rousseau</dc:creator>
      <dc:date>2015-06-04T15:41:34Z</dc:date>
    </item>
    <item>
      <title>I have 2 ASA 5525X FirePOWER</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662735#M103719</link>
      <description>&lt;P&gt;I have 2 ASA 5525X FirePOWER added to my FireSIGHT manager, I added FireSIGHT host and User license, and 2 Malware Licenses for ASA5525, but My Devices License Type shows 'Unlicensed".&lt;/P&gt;
&lt;P&gt;I don't know where to start fixing this, I'm with SourceFire stuff.&lt;/P&gt;
&lt;P&gt;I don't know, maybe I'm missing something&lt;/P&gt;
&lt;P&gt;Please help&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 16:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662735#M103719</guid>
      <dc:creator>Sandile Mazamane</dc:creator>
      <dc:date>2015-11-05T16:41:48Z</dc:date>
    </item>
    <item>
      <title>Hi Sandile,</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662736#M103720</link>
      <description>&lt;P&gt;Hi Sandile,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You need to edit the device and add the license that you have uploaded to the Management Centre.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 22:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662736#M103720</guid>
      <dc:creator>bbogdane</dc:creator>
      <dc:date>2015-11-05T22:02:28Z</dc:date>
    </item>
    <item>
      <title>Hi Sandi,</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662737#M103721</link>
      <description>&lt;P&gt;Hi Sandi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please add the PROTECT+CONTROL license for the ASA5525, there should be a PAK sent along with the device. Please register the PAK to obtain the license for "PROTECT+CONTROL".&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;- DD&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 00:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662737#M103721</guid>
      <dc:creator>dhvenkat</dc:creator>
      <dc:date>2015-11-06T00:18:05Z</dc:date>
    </item>
    <item>
      <title>The PAKs I got gave me only</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662738#M103722</link>
      <description>&lt;P&gt;The PAKs I got gave me only the licenses you see on the images. Part number&amp;nbsp;L-ASA5525-TAMC&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 09:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662738#M103722</guid>
      <dc:creator>Sandile Mazamane</dc:creator>
      <dc:date>2015-11-06T09:26:28Z</dc:date>
    </item>
    <item>
      <title>Sandlike,</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662739#M103723</link>
      <description>&lt;P&gt;Sandile,&lt;/P&gt;
&lt;P&gt;The Protect+Control PAK is delivered as a paper PAK in the box with the appliance. It is a zero cost item delivered with all FirePOWER modules. If it has been misplaced, the vendor can call it up on the Cisco ordering system.&lt;/P&gt;
&lt;P&gt;You need to redeem that PAK and apply the license as a prerequisite for any of the other licenses.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 12:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/2662739#M103723</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-11-06T12:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: technically it would work.</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/3175992#M103724</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;Thank you for your iput. Perhaps this is a matter of symantics with the words licensing vs subscription which is why I need clarification. I have two ASA5512X Appliances with FirePower Services (ASA5512-FPWR-K9) in Active/Standby mode. I am now looking to purchase the necessary subscription, specifically "Cisco ASA with FirePOWER Services IPS, Advanced Malware Protection and URL Subscription" (Mfg. Part#: L-ASA5512-TAMC-1Y). Do I need to purchase a quantity of two subscriptions - one for each appliance? In other words, do I need to purchase a subscription for the standby unit? Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 18:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/3175992#M103724</guid>
      <dc:creator>KK Admin</dc:creator>
      <dc:date>2017-08-25T18:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: technically it would work.</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/3176098#M103725</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/340991"&gt;@KK Admin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes - both the Active and Standby units require their own subscription.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Aug 2017 04:19:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/3176098#M103725</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-26T04:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5512 Active/Standby with Firepower services</title>
      <link>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/3205775#M103726</link>
      <description>&lt;P&gt;I have the same situation. This answer is helpful. Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 14:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5512-active-standby-with-firepower-services/m-p/3205775#M103726</guid>
      <dc:creator>abjohnson</dc:creator>
      <dc:date>2017-10-26T14:40:58Z</dc:date>
    </item>
  </channel>
</rss>

