<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FirePower Appliance Placement in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043164#M1067581</link>
    <description>&lt;P&gt;I have a FirePower 8k series appliance that is tied together with ISE pxGrid.&amp;nbsp; Currently, the FP is setup with 2 ports inline on the outside of the firewall(ASA).&amp;nbsp; I have a SPAN on the inside of the firewall that sends trafic to another port on the FP acting as an IDS.&amp;nbsp; Using passive identity with no SGTs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the identity info when traffic is seen inside but once it goes out the firewall it is lost.&amp;nbsp; Is there a way to preserve that data or should I plan to bring the IPS inside the firewall?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Mar 2020 03:32:37 GMT</pubDate>
    <dc:creator>rsharp001</dc:creator>
    <dc:date>2020-03-10T03:32:37Z</dc:date>
    <item>
      <title>FirePower Appliance Placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043164#M1067581</link>
      <description>&lt;P&gt;I have a FirePower 8k series appliance that is tied together with ISE pxGrid.&amp;nbsp; Currently, the FP is setup with 2 ports inline on the outside of the firewall(ASA).&amp;nbsp; I have a SPAN on the inside of the firewall that sends trafic to another port on the FP acting as an IDS.&amp;nbsp; Using passive identity with no SGTs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the identity info when traffic is seen inside but once it goes out the firewall it is lost.&amp;nbsp; Is there a way to preserve that data or should I plan to bring the IPS inside the firewall?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 03:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043164#M1067581</guid>
      <dc:creator>rsharp001</dc:creator>
      <dc:date>2020-03-10T03:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower Appliance Placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043480#M1067612</link>
      <description>&lt;P&gt;The identity integration associates a given username with the IP address of the endpoint where that user was authenticated. If the outside traffic has been NATted, you lose that association information.&lt;/P&gt;
&lt;P&gt;You can only see the end to end flow using something like StealthWatch which can stitch together flows from records originating from an ASA or FTD firewall using the NSEL type of Netflow records which include the NAT translation information.&lt;/P&gt;
&lt;P&gt;Otherwise, yes - you would need to have the IPS inside. That is the recommended placement for IPS' (generally speaking) when they are distinct from the firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 14:30:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043480#M1067612</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-03-10T14:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower Appliance Placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043524#M1067613</link>
      <description>Aside from NAT that Marvin mentioned, you would lose the SGT unless you were doing inline tagging between devices (within the network).</description>
      <pubDate>Tue, 10 Mar 2020 15:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043524#M1067613</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-03-10T15:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower Appliance Placement</title>
      <link>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043547#M1067614</link>
      <description>&lt;P&gt;Thank you Marvin.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-appliance-placement/m-p/4043547#M1067614</guid>
      <dc:creator>rsharp001</dc:creator>
      <dc:date>2020-03-10T16:23:33Z</dc:date>
    </item>
  </channel>
</rss>

