<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Source Fire HA pair in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873160#M162002</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a question in regards to the Cisco SourceFire. I have a pair of ASA5525x setup for HA. My question is does the SourceFire work as a HA pair or do they operate individually? So far it&amp;nbsp;looks as they are operate individually.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-Alex&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:30:42 GMT</pubDate>
    <dc:creator>alex.vue</dc:creator>
    <dc:date>2019-03-12T07:30:42Z</dc:date>
    <item>
      <title>Cisco Source Fire HA pair</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873160#M162002</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a question in regards to the Cisco SourceFire. I have a pair of ASA5525x setup for HA. My question is does the SourceFire work as a HA pair or do they operate individually? So far it&amp;nbsp;looks as they are operate individually.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-Alex&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873160#M162002</guid>
      <dc:creator>alex.vue</dc:creator>
      <dc:date>2019-03-12T07:30:42Z</dc:date>
    </item>
    <item>
      <title>Individually.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873161#M162003</link>
      <description>&lt;P&gt;Individually.&lt;/P&gt;
&lt;P&gt;The FirePOWER modules share neither configuration nor connection state on their own. That's in contrast to the base ASAs which share both.&lt;/P&gt;
&lt;P&gt;If you use FirePOWER Management Center, you can build policies once and deploy to them both (or as many as you have in your network). State remains per module.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 01:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873161#M162003</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-18T01:07:53Z</dc:date>
    </item>
    <item>
      <title>Thank you Marvin for your</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873162#M162004</link>
      <description>&lt;P&gt;Thank you Marvin for your clarification.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As for the management Center (FireSight), I don't see any documentation on HA. Does it not have HA capability? I ask because NCS (Cisco Prime) has the HA capability.&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 15:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873162#M162004</guid>
      <dc:creator>alex.vue</dc:creator>
      <dc:date>2016-03-18T15:38:46Z</dc:date>
    </item>
    <item>
      <title>FirePOWER Management Center</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873163#M162005</link>
      <description>&lt;P&gt;FirePOWER Management Center high availability (HA) pairing requires like/like hardware and this can only be verified on hardware appliances and not virtual.&lt;/P&gt;
&lt;P&gt;As for HA pairing, when FireSIGHT Managers are paired all configuration data is automatically replicated between them, ensuring redundancy from a management perspective.&amp;nbsp; This high-availability or redundancy feature helps ensure continuity of operations. The secondary Cisco FireSIGHT Management Center must be the same model as the primary appliance.&lt;/P&gt;
&lt;P&gt;Here is the User Guide section on setting up HA:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/Managing-Devices.html#pgfId-7819313&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 17:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873163#M162005</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-18T17:51:59Z</dc:date>
    </item>
    <item>
      <title>Thanks again Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873164#M162006</link>
      <description>&lt;P&gt;Thanks again Marvin.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 17:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873164#M162006</guid>
      <dc:creator>alex.vue</dc:creator>
      <dc:date>2016-03-18T17:55:47Z</dc:date>
    </item>
    <item>
      <title>Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873165#M162007</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I still have my 2 ASAs in the lab along with the FireSight management. I'm afraid to register my&amp;nbsp;FireSight management. &amp;nbsp;My question is if I registered the FireSight management license in my lab, will it be a problem when I bring it into production? What is the best option as far as moving the FireSight into production? Re-deploy the&amp;nbsp;downloaded OVF from Cisco&amp;nbsp;or captured the LAB OS and re-deploy in production? By the way, I am using VMware.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 18 Mar 2016 22:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873165#M162007</guid>
      <dc:creator>alex.vue</dc:creator>
      <dc:date>2016-03-18T22:59:40Z</dc:date>
    </item>
    <item>
      <title>@alex.vue@DOC  ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873166#M162008</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[@alex.vue@DOC]&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;Re the lab-production question, I wouldn't say there's any one answer that's right for every situation.&lt;/P&gt;
&lt;P&gt;The license key that a given FireSIGHT / FirePOWER Management Center uses is derived from a combination of the model type and the VM's MAC address. So if you snapshot or vMotion the VM onto another ESXi host, the MAC address (and thus the license key) generally will transfer with it.&lt;/P&gt;
&lt;P&gt;I'm not a VMware expert by any stretch but I know that an ESXi server dynamically generates MAC addresses for its VMs when they're created. If you import them as a fait accompli I believe it lets the MAC address stand as long as there's no conflict with one it already has allocated to another VM.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What license are you using in the lab? You have to have a Management Center license active in order to deploy policies. If you don't have one redeemed yet then it's a moot point. Since the Management Center license is perpetual it is no harm to redeem it as soon as you are ready to use it - in lab or production. If worse came to worse and you blew it up somehow, you could always request it be rehosted by the Cisco licensing team. They're generally OK with that if it's for a legitimate reason.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2016 23:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873166#M162008</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-20T23:30:26Z</dc:date>
    </item>
    <item>
      <title>Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873167#M162009</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;First of all, thanks for taking your time to reply on this matter.&lt;/P&gt;
&lt;P&gt;I dug through Cisco Guide and documentation and found this:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/541/virtual-install-guide/FireSIGHT-Virtual-Installation-Guide/V-Intro.html#97125&lt;/P&gt;
&lt;H3 class="p_H_Head2"&gt;&lt;A name="pgfId-2952055"&gt;&lt;/A&gt;&lt;A name="Guidelines_and_Limitations"&gt;&lt;/A&gt;&lt;A name="37939"&gt;&lt;/A&gt;Guidelines and Limitations&lt;/H3&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-2952059"&gt;&lt;/A&gt;The following limitations exist when deploying virtual Defense Center or devices on VMware:&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="pBu1_Bullet1"&gt;&lt;A name="pgfId-2952060"&gt;&lt;/A&gt;vMotion is not supported.&lt;/LI&gt;
&lt;LI class="pBu1_Bullet1"&gt;&lt;A name="pgfId-2952061"&gt;&lt;/A&gt;Cloning a virtual machine is not supported.&lt;/LI&gt;
&lt;LI class="pBu1_Bullet1"&gt;&lt;A name="pgfId-2952062"&gt;&lt;/A&gt;Restoring a virtual machine with a snapshot is not supported.&lt;/LI&gt;
&lt;LI class="pBu1_Bullet1"&gt;&lt;A name="pgfId-2952063"&gt;&lt;/A&gt;Restoring a backup is not supported.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So I guess there is no HA capability available for virtual?&lt;/P&gt;
&lt;P&gt;Will the configured policies stay on the ASA even if the FireSIGHT virtual appliance fail?&lt;/P&gt;
&lt;P&gt;My assumption is FireSIGHT is similar to Cisco Prime Infrastructure where it pushes configs to the managed device?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 17:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873167#M162009</guid>
      <dc:creator>alex.vue</dc:creator>
      <dc:date>2016-03-21T17:28:37Z</dc:date>
    </item>
    <item>
      <title>They are a bit paranoid about</title>
      <link>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873168#M162010</link>
      <description>&lt;P&gt;They are a bit paranoid about the vMotion/cloning/snapshot issues. I expect that will change going forward but you're correct in citing that as the current official line.&lt;/P&gt;
&lt;P&gt;With respect to policies - yes - if the management Center goes away or offline or is otherwise unreachable, all deployed policies remain in place and enforcing rules as configured on the managed devices. Events are stored locally on the sensor (up to its capacity) and then synced to the FMC once it is again reachable.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 21:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-source-fire-ha-pair/m-p/2873168#M162010</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-21T21:27:35Z</dc:date>
    </item>
  </channel>
</rss>

