<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD or ASA OS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490180#M133085</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;in the anyconnect the FTD have some limitations&lt;/SPAN&gt;&lt;/P&gt;&lt;H2 style="margin-top: 23px; margin-bottom: 3px; font-size: 18px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;&lt;SPAN style="font-size: 14pt;"&gt;Limitations&lt;/SPAN&gt;&lt;/H2&gt;&lt;P style="margin-bottom: 6px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;Currently unsupported on FTD, but available on ASA:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Double AAA Authentication&lt;/LI&gt;&lt;LI&gt;Dynamic Access Policy&lt;/LI&gt;&lt;LI&gt;Host Scan&lt;/LI&gt;&lt;LI&gt;ISE posture&lt;/LI&gt;&lt;LI&gt;RADIUS CoA&lt;/LI&gt;&lt;LI&gt;VPN load-balancer&lt;/LI&gt;&lt;LI&gt;Local authentication (Enhancement: &lt;A href="https://tools.cisco.com/bugsearch/bug/CSCvf92680" rel="nofollow noopener noreferrer" style="font-style: inherit; font-family: inherit; color: #6f53bc;" target="_blank"&gt;CSCvf92680&lt;/A&gt;&lt;A href="https://techzone.cisco.com/" rel="nofollow noopener noreferrer" style="font-style: inherit; font-family: inherit; color: #6f53bc;"&gt;&lt;IMG border="0" class="jive-image" src="https://techzone.cisco.com/html/assets/mag.gif" style="border-width: 0px; font-style: inherit; font-weight: inherit; font-size: inherit; font-family: inherit;" title="Bug-Preview for CSCvf92680" /&gt;&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;LDAP attribute map&lt;/LI&gt;&lt;LI&gt;AnyConnect customization&lt;/LI&gt;&lt;LI&gt;AnyConnect scripts&lt;/LI&gt;&lt;LI&gt;AnyConnect localization&lt;/LI&gt;&lt;LI&gt;Per-app VPN&lt;/LI&gt;&lt;LI&gt;SCEP proxy&lt;/LI&gt;&lt;LI&gt;WSA integration&lt;/LI&gt;&lt;LI&gt;SAML SSO&lt;/LI&gt;&lt;LI&gt;Simultaneous IKEv2 dynamic crypto map for RA and L2L VPN&lt;/LI&gt;&lt;LI&gt;AnyConnect modules (NAM, Hostscan, AMP Enabler etc.) – DART is installed by default&lt;/LI&gt;&lt;LI&gt;TACACS, Kerberos (KCD Authentication and RSA SDI)&lt;/LI&gt;&lt;LI&gt;Browser Proxy&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can check this guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html" title="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html"&gt;AnyConnect Remote Access VPN configuration on FTD - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Feb 2018 07:34:59 GMT</pubDate>
    <dc:creator>cenriquez</dc:creator>
    <dc:date>2018-02-08T07:34:59Z</dc:date>
    <item>
      <title>FTD or ASA OS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490176#M133073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems Cisco made decision to go with FTD as only image for NGFW. Is anyone here who alrady implemented FTD across company (not pilot, not single firwall) ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 08:03:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490176#M133073</guid>
      <dc:creator>stcnetteam</dc:creator>
      <dc:date>2017-12-13T08:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: FTD or ASA OS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490177#M133077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have around 10 implementations with FTD. I can tell you will give you&amp;nbsp; a little pain in the head because there is some features that you need to work hard to delivery everything like customers want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL/TLS decryption is the most trick feature imo. There is no many options to make a exception ( you can not add a external feed list to exclude. ex: office 365 ). You only can use URL categories and others SSL/TLS options to do this and, imo, is not the best way to to this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FMC 6.2.2.1 is too slow if you comper if others vendor. But is much better now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I like ASA a lot, working with Firepower about a 2 years need much improve to beat firewalls solutions like paloalto and fortnet. ( its sad but its true )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw all implementations was sucessfull. If you need some help we can help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Pablo Costa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 16:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490177#M133077</guid>
      <dc:creator>pablo.costa</dc:creator>
      <dc:date>2017-12-13T16:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: FTD or ASA OS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490178#M133080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Pablo, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for answer.&lt;/P&gt;&lt;P&gt;What about VPN functionalities. Both S2S VPN and AnyConnect Remote Access (group polices, Dynamic Access Polices, XML profiles)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2017 19:47:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490178#M133080</guid>
      <dc:creator>stcnetteam</dc:creator>
      <dc:date>2017-12-13T19:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD or ASA OS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490179#M133082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FTD now supports S2S VPN and RA VPN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also deployed multiple FTDs for multiple customers in production. I have done many S2S VPNs. I have labbed up the AnyConnect RA VPN, as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't believe Dynamic Access Policies are supported at this time. But, depending on what you're using it for, you may have other options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have specific use cases you want to confirm are available, you probably want to chat with your partner/account team.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Dec 2017 18:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490179#M133082</guid>
      <dc:creator>Ryan Wolfe</dc:creator>
      <dc:date>2017-12-15T18:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: FTD or ASA OS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490180#M133085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;in the anyconnect the FTD have some limitations&lt;/SPAN&gt;&lt;/P&gt;&lt;H2 style="margin-top: 23px; margin-bottom: 3px; font-size: 18px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;&lt;SPAN style="font-size: 14pt;"&gt;Limitations&lt;/SPAN&gt;&lt;/H2&gt;&lt;P style="margin-bottom: 6px; font-size: 14px; font-family: CiscoSans, Arial, sans-serif; color: #58585b;"&gt;Currently unsupported on FTD, but available on ASA:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Double AAA Authentication&lt;/LI&gt;&lt;LI&gt;Dynamic Access Policy&lt;/LI&gt;&lt;LI&gt;Host Scan&lt;/LI&gt;&lt;LI&gt;ISE posture&lt;/LI&gt;&lt;LI&gt;RADIUS CoA&lt;/LI&gt;&lt;LI&gt;VPN load-balancer&lt;/LI&gt;&lt;LI&gt;Local authentication (Enhancement: &lt;A href="https://tools.cisco.com/bugsearch/bug/CSCvf92680" rel="nofollow noopener noreferrer" style="font-style: inherit; font-family: inherit; color: #6f53bc;" target="_blank"&gt;CSCvf92680&lt;/A&gt;&lt;A href="https://techzone.cisco.com/" rel="nofollow noopener noreferrer" style="font-style: inherit; font-family: inherit; color: #6f53bc;"&gt;&lt;IMG border="0" class="jive-image" src="https://techzone.cisco.com/html/assets/mag.gif" style="border-width: 0px; font-style: inherit; font-weight: inherit; font-size: inherit; font-family: inherit;" title="Bug-Preview for CSCvf92680" /&gt;&lt;/A&gt;)&lt;/LI&gt;&lt;LI&gt;LDAP attribute map&lt;/LI&gt;&lt;LI&gt;AnyConnect customization&lt;/LI&gt;&lt;LI&gt;AnyConnect scripts&lt;/LI&gt;&lt;LI&gt;AnyConnect localization&lt;/LI&gt;&lt;LI&gt;Per-app VPN&lt;/LI&gt;&lt;LI&gt;SCEP proxy&lt;/LI&gt;&lt;LI&gt;WSA integration&lt;/LI&gt;&lt;LI&gt;SAML SSO&lt;/LI&gt;&lt;LI&gt;Simultaneous IKEv2 dynamic crypto map for RA and L2L VPN&lt;/LI&gt;&lt;LI&gt;AnyConnect modules (NAM, Hostscan, AMP Enabler etc.) – DART is installed by default&lt;/LI&gt;&lt;LI&gt;TACACS, Kerberos (KCD Authentication and RSA SDI)&lt;/LI&gt;&lt;LI&gt;Browser Proxy&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can check this guide&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html" title="https://www.cisco.com/c/en/us/support/docs/network-management/remote-access/212424-anyconnect-remote-access-vpn-configurati.html"&gt;AnyConnect Remote Access VPN configuration on FTD - Cisco&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 07:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490180#M133085</guid>
      <dc:creator>cenriquez</dc:creator>
      <dc:date>2018-02-08T07:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: FTD or ASA OS</title>
      <link>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490181#M133087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been on a project for the past few months deploying ASA5516s converted to FTDs. The conversion takes about 3 hours. The FTDs are configured in a HA pair with no issues so far. The routing protocol is EIGRP so I had to use Flexconfig. Flexconfig takes a little time to get used to and it has been good. We had an issue with EIGRP authentication and Cisco has released a patch to us to take care of that issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With FTDs you do give up CLI configuration and that can slow down the configuration process, especially with the HA pair.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Feb 2018 20:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-or-asa-os/m-p/3490181#M133087</guid>
      <dc:creator>msanclimenti</dc:creator>
      <dc:date>2018-02-08T20:05:59Z</dc:date>
    </item>
  </channel>
</rss>

