<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower can limit current session or not in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401612#M1080706</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean firepower can limit concurrent session or not . Refer from datasheet example. Firepower 4110 can handle&amp;nbsp;&lt;STRONG&gt;Concurrent firewall connections 10million&amp;nbsp;&lt;/STRONG&gt; but If We need to limit concurrent by policy/ip/protocol not ACL configuration . Firepower can do it and if can do&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower can alert or send alarm while concurrent session reach limit sessions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for help&lt;/P&gt;</description>
    <pubDate>Wed, 12 May 2021 04:47:16 GMT</pubDate>
    <dc:creator>jewfcb001</dc:creator>
    <dc:date>2021-05-12T04:47:16Z</dc:date>
    <item>
      <title>Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400905#M1080676</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco firepower running asa image&amp;nbsp;can limit current session or not ?&lt;/P&gt;&lt;P&gt;limit by policy/ip/protocol ?&lt;/P&gt;&lt;P&gt;I try to find document but i not found.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me.&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 08:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400905#M1080676</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-05-11T08:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400944#M1080677</link>
      <description>&lt;P&gt;Yes you can do that. And as always there are multiple options. Start with looking into VPN-Filters as they are likely to fit your needs:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa912/asdm712/vpn/asdm-712-vpn-config/vpn-asdm-setup.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa912/asdm712/vpn/asdm-712-vpn-config/vpn-asdm-setup.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 09:21:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400944#M1080677</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2021-05-11T09:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400945#M1080678</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp; thank you your answer . can you share document to me ? for VPN-Filters you mean can limit session on VPN session ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 09:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400945#M1080678</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-05-11T09:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400996#M1080682</link>
      <description>&lt;P&gt;There are examples in the config-guide. The VPN-Filter is an ACL that gets attached to a group-policy. Only traffic permitted in the ACL is allowed for the VPN-client.&lt;/P&gt;
&lt;P&gt;Here is an example where the sales group is only allowed DNS to .53 and HTTPS to .80:&lt;/P&gt;
&lt;PRE&gt;access-list VPN-FILTER-SALES extended permit udp any host 10.10.10.53 eq domain
access-list VPN-FILTER-SALES extended permit tcp any host 10.10.10.80 eq https
!
group-policy VPN-SALES internal
group-policy VPN-SALES attributes
  vpn-filter value VPN-FILTER-SALES
  &lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 11:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4400996#M1080682</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2021-05-11T11:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401143#M1080686</link>
      <description>&lt;P&gt;I'm still confuse . How this configuration can limit concurrent session by policy/ip/protocol ?&lt;/P&gt;&lt;P&gt;My understand the current session can limit of number of current session. . If my understand not correct . Please let&amp;nbsp; me know .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 13:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401143#M1080686</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-05-11T13:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401153#M1080687</link>
      <description>&lt;P&gt;Perhaps I did not get what you exactly want. The VPN-filter limits which IP/protocol/ports can be used in that VPN-Session. Can you describe in more detail what you want to achieve?&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 14:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401153#M1080687</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2021-05-11T14:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401612#M1080706</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean firepower can limit concurrent session or not . Refer from datasheet example. Firepower 4110 can handle&amp;nbsp;&lt;STRONG&gt;Concurrent firewall connections 10million&amp;nbsp;&lt;/STRONG&gt; but If We need to limit concurrent by policy/ip/protocol not ACL configuration . Firepower can do it and if can do&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower can alert or send alarm while concurrent session reach limit sessions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for help&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 04:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401612#M1080706</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-05-12T04:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401664#M1080707</link>
      <description>&lt;P&gt;Ok, now I understand what you want. Yes, this can also be done. But the config is based on the modular policy framework (MPF) and it will be quite some work to implement it for different IPs and/or protocols:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/firewall/asa-914-firewall-config/conns-connlimits.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/firewall/asa-914-firewall-config/conns-connlimits.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For the alarms, you would typically write some log-checking rules on your syslog server.&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 06:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401664#M1080707</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2021-05-12T06:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower can limit current session or not</title>
      <link>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401682#M1080708</link>
      <description>&lt;P&gt;Thank you for your answer .&lt;/P&gt;&lt;P&gt;I try to understand from your URL . My understand is The limit concurrent session can do under policy map/global policy . and configure with acl together . and set maximum connection following command&amp;nbsp;&amp;nbsp;set connection conn-max&amp;nbsp;under policy-map but the value can configure&amp;nbsp;0 and 2000000 , So if Firepower can handle session more than 2milion the value can change more than 2milion or not ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 07:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-can-limit-current-session-or-not/m-p/4401682#M1080708</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2021-05-12T07:06:34Z</dc:date>
    </item>
  </channel>
</rss>

