<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL rewrite on ASA platform in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528268#M1086259</link>
    <description>&lt;P&gt;&lt;A href="https://ciscocentral.blogspot.com/p/300-725-securing-web-with-cisco-web.html" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cisco AnyConnect&lt;/STRONG&gt;&lt;/A&gt; is a uniform security endpoint agent which deliver multiple security services to protect the enterprise. Also, it provides visibility along with the control which is required you to identify who and which devices are accessing the extended enterprise.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jan 2022 04:26:32 GMT</pubDate>
    <dc:creator>alirafaleiro</dc:creator>
    <dc:date>2022-01-20T04:26:32Z</dc:date>
    <item>
      <title>SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528189#M1086254</link>
      <description>&lt;P&gt;Some questions about the latest ASAs out there.&amp;nbsp;Client is getting ready to replace their aging Cisco firewalls (5525s, no FP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to&amp;nbsp;AnyConnect to new ASAs w/2FA and then redirect user's web session via an SSL rewrite to a backend server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For clients that already have NGFW services elsewhere, is it possible to run a new ASA without FP active and/or installed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current redundancy is Active/Standby and they need fiber/SFP failover redundancy port connections. Do the SFP ports on the new ASAs allow use for failover?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since there is no hardware upgrade tool online, my best estimate currently is the 2100 line to replace the 5525s if the SFP ports can be used for back to back failover connections.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 23:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528189#M1086254</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-01-07T23:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528232#M1086256</link>
      <description>&lt;P&gt;s it possible to&amp;nbsp;AnyConnect to new ASAs w/2FA and then redirect user's web session via an SSL rewrite to a backend server?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BB - as i understand you looking to redirect to the portal? why do you like to do this, as the user already trusted and made 2 facto identify as trust user?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For clients that already have NGFW services elsewhere, is it possible to run a new ASA without FP active and/or installed?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BB - i do not see any issue until i interpret this as different from your original requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current redundancy is Active/Standby and they need fiber/SFP failover redundancy port connections. Do the SFP ports on the new ASAs allow use for failover?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BB -&amp;nbsp; depends on the Model here&amp;nbsp; - yes you can have a sync link using SFP or Ethernet.&lt;/P&gt;
&lt;P&gt;check ASA Model has SFP port :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/security/asa-5500-series-next-generation-firewalls/data_sheet_c78-345385.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/security/asa-5500-series-next-generation-firewalls/data_sheet_c78-345385.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since there is no hardware upgrade tool online, my best estimate currently is the 2100 line to replace the 5525s if the SFP ports can be used for back to back failover connections.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BB - 2100 is good to replace the model you mentioned ASA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FP2100 do have SFP ports check datasheet :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firepower-2100-series/datasheet-c78-742473.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/firepower-2100-series/datasheet-c78-742473.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 07:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528232#M1086256</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-01-08T07:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528268#M1086259</link>
      <description>&lt;P&gt;&lt;A href="https://ciscocentral.blogspot.com/p/300-725-securing-web-with-cisco-web.html" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Cisco AnyConnect&lt;/STRONG&gt;&lt;/A&gt; is a uniform security endpoint agent which deliver multiple security services to protect the enterprise. Also, it provides visibility along with the control which is required you to identify who and which devices are accessing the extended enterprise.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 04:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528268#M1086259</guid>
      <dc:creator>alirafaleiro</dc:creator>
      <dc:date>2022-01-20T04:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528355#M1086264</link>
      <description>&lt;P&gt;Thanks for your reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding SSL rewrite requirement, that was specified by the Architect for this project. All I know is this is a requirement, but I still do not see this capability on the newer Cisco firewalls.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if there is a SKU to order a 2100 w/o FP?&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 17:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528355#M1086264</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-01-08T17:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528358#M1086265</link>
      <description>&lt;PRE&gt;Do you know if there is a SKU to order a 2100 w/o FP?&lt;/PRE&gt;
&lt;P&gt;what do you mean W/o FP, by Default&amp;nbsp; 2100 ship with Firepower, if you like to with ASA on top of it, you need to re-image with ASA.&lt;/P&gt;
&lt;P&gt;the above post provides you datasheet to ordering guide : (if you have concerns, i would advise to a local partner who can assist you better).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have seen some people buying this product later it can not be replaced as expected. so suggest to contact local partner and understand requirement and guide you better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FP2100 do have SFP ports check datasheet :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firepower-2100-series/datasheet-c78-742473.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/products/collateral/security/firepower-2100-series/datasheet-c78-742473.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 17:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528358#M1086265</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-01-08T17:53:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528360#M1086266</link>
      <description>working with a partner next week thanks just trying to get started on the weekend.&lt;BR /&gt;</description>
      <pubDate>Sat, 08 Jan 2022 17:56:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528360#M1086266</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-01-08T17:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528361#M1086267</link>
      <description>&lt;P&gt;Sure i understand, you also need more hands-on information before you talk to your partner.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jan 2022 17:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528361#M1086267</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-01-08T17:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528421#M1086269</link>
      <description>&lt;P&gt;"SSL rewrite" is not possible with a Firepower appliance by itself - whether running FTD or ASA image.&lt;/P&gt;
&lt;P&gt;If you use ISE as the AAA server you can push a redirect ACL as part of the Authorization result.&lt;/P&gt;
&lt;P&gt;All Firepower hardware appliances can be ordered with either FTD or ASA software as part of the initial order.&lt;/P&gt;
&lt;P&gt;We seldom see them ordered with ASA software though since that means you will not be able to run any of the NGIPS, Malware or URL Filtering features. You will also have to continue to manage the configuration via ASDM or cli (or possibly CDO) vs. FMC with its richer analysis and event management features.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jan 2022 03:13:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4528421#M1086269</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-01-09T03:13:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSL rewrite on ASA platform</title>
      <link>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4531770#M1086446</link>
      <description>Thank you for your reply. I'm not the architect of this design, otherwise even if they were redundant/overlapping, I'd have NGFW services on the ASA and in the cloud where they currently exist.&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Jan 2022 19:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssl-rewrite-on-asa-platform/m-p/4531770#M1086446</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2022-01-14T19:20:27Z</dc:date>
    </item>
  </channel>
</rss>

