<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do I need Threat License with FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459404#M1083314</link>
    <description>&lt;P&gt;Perfect, these are the answers I needed to know.&amp;nbsp; Appears we are using IPS within our ACP rules, so will get Threat quoted.&amp;nbsp; Will look to get both Threat and URL together so its easier to renew each time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ken~&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 13:00:55 GMT</pubDate>
    <dc:creator>Ken C. Musk</dc:creator>
    <dc:date>2021-09-03T13:00:55Z</dc:date>
    <item>
      <title>Do I need Threat License with FTD</title>
      <link>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4458996#M1083299</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;I am starting to convert all my 5516x ASA with FirePower Services over to the full FTD image.&amp;nbsp; I have 22 total to convert and have successfully converted 4 of them over.&amp;nbsp; Now that those 4 are on full FTD image I need to use Smart Licensing instead of the Classic Licensing.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the old Classic Licensing we have Control/Protection which is perpetual, but with Smart Licensing Protection turns into Threat and is a renewable license.&amp;nbsp; Cisco says I only need this Threat license if I am using IPS, and honestly not sure if I am.&amp;nbsp; Pretty sure I am since the symbol within the ACP is checked under inspection.&amp;nbsp; We had a third party set all these up years ago, but now I get to learn and take them over...&lt;/P&gt;&lt;P&gt;Are the system provided Intrusion Policy's part of threat or just if I create my own Intrusion Policy?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Speaking with TAC and well its clear as mud so figured I would ask here.&amp;nbsp; My newly created ACP are VERY basic for what we do.&amp;nbsp; We do have URL Filtering, but no AMP.&amp;nbsp; Within my ACP rules if I set the Intrusion to None what am I really gaining or missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ken~&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 18:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4458996#M1083299</guid>
      <dc:creator>Ken C. Musk</dc:creator>
      <dc:date>2021-09-02T18:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need Threat License with FTD</title>
      <link>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459038#M1083301</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/198397"&gt;@Ken C. Musk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the threat license it has 3 features : IPS, File control and Security intelligence filtering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are the system provided Intrusion Policy's part of threat or just if I create my own Intrusion Policy? You can create IPS policy with no base policy (system provided ips policy) &lt;STRONG&gt;BUT&lt;/STRONG&gt; Without Threat license enabled you cannot deploy an ACP contains IPS enabled.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Within my ACP rules if I set the Intrusion to None what am I really gaining or missing? As you know IPS used for deep analyse the flow for exploits, Downloaded viruses and so on, so it's obvious what you are missing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you are using URL Filtering then you need even the URL license.&lt;BR /&gt;Both of these licenses are term-based which means you can purshase them for 1 year, 3 years, or 5 years.&lt;BR /&gt;&lt;BR /&gt;For more detailled info's :&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Licensing_the_Firepower_System.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Licensing_the_Firepower_System.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope that helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 19:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459038#M1083301</guid>
      <dc:creator>Amine ZAKARIA</dc:creator>
      <dc:date>2021-09-02T19:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need Threat License with FTD</title>
      <link>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459047#M1083302</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/198397"&gt;@Ken C. Musk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;First of all, Control/Protect license is a license that activates IPS. Although it is displayed in FMC as perpetual, it actually isn't, and it is expected from you to purchase it on regular basis. With Smart Licensing, this is much easier to understand, as you get clear visibility on your Smart Account portal.&lt;/P&gt;&lt;P&gt;You can easily verify whether you are using IPS or not, if you take a look at your Access Control Policy, as it must be enabled under rules there (in rule, under Inspection tab):&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 879px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/129519iDC6E40703A93E25C/image-dimensions/879x266?v=v2" width="879" height="266" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here you can also see which policy are you using.&lt;/P&gt;&lt;P&gt;Yes, you can use system predefined ones (there are few), but I would recommend creating your own.&lt;/P&gt;&lt;P&gt;URL filtering is quite different service from IPS. IPS provides protection against malicious attempts to breach your infrastructure, while URL filtering is mostly used to control what your users can access to.&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 19:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459047#M1083302</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-09-02T19:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Do I need Threat License with FTD</title>
      <link>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459404#M1083314</link>
      <description>&lt;P&gt;Perfect, these are the answers I needed to know.&amp;nbsp; Appears we are using IPS within our ACP rules, so will get Threat quoted.&amp;nbsp; Will look to get both Threat and URL together so its easier to renew each time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ken~&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/do-i-need-threat-license-with-ftd/m-p/4459404#M1083314</guid>
      <dc:creator>Ken C. Musk</dc:creator>
      <dc:date>2021-09-03T13:00:55Z</dc:date>
    </item>
  </channel>
</rss>

