<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Marvin,  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862311#M167102</link>
    <description>&lt;P&gt;Hi Marvin,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the answer, one question more the relicense has no cost? Or the costumer must buy the license.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2017 16:05:30 GMT</pubDate>
    <dc:creator>bernardovr</dc:creator>
    <dc:date>2017-08-17T16:05:30Z</dc:date>
    <item>
      <title>Cisco ASA FTD vs Firepower Software</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862295#M167086</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am confused between Firepower FTD stuff and Firepower Services Software.&amp;nbsp;So following are my questions based on what I understood:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;With &lt;STRONG&gt;Firepower Services Software module:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;1. You have your normal ASA OS and then you download the Firepower Services Software. Or is the compatible firewall always shipped with the&amp;nbsp;&lt;SPAN&gt;Firepower Services Software pre installed?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. So ASA will do - Routing, ACLs, NAT, VPN&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Firepower Services Software will do - AVC, URL Filtering, NGIPS and AMP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is this understanding correct?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. ASA as well as Firepower Services Software&amp;nbsp;can be managed by ASDM and CLI. But only&amp;nbsp;Firepower Services Software can be managed by Firepower Management Center i.e. only the above mentioned 4 functions of&amp;nbsp;Firepower Services Software can be controlled by Firepower Management Center.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;With FTD Image&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;4. There is only one image on the firewall. Correct? &amp;nbsp;(I say image because to install FTD I somehow need 2 files: like a *.lfbff file. and a .pkg file. Still confused why)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;5. All&amp;nbsp;the functions mentioned above for&amp;nbsp;ASA as well as those provided by&amp;nbsp;&lt;SPAN&gt;Firepower Services Software will be managed ONLY by Firepower Management Center. That means even if I have to add a simple ACE then I need to do it using the Management Center? Correct?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please Clarify. Everything &amp;nbsp;with FTD/Firepower is really confusing. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862295#M167086</guid>
      <dc:creator>rjadhav163</dc:creator>
      <dc:date>2019-03-12T07:45:48Z</dc:date>
    </item>
    <item>
      <title>1. The ASA is available both</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862296#M167087</link>
      <description>&lt;P&gt;1. The ASA is available both with and without the FirePOWER software module pre-installed. It no extra cost to specify it with so we (my company that it and other partners) typically specify it with so that it's already there in case the customer wants to activate it later.&lt;/P&gt;
&lt;P&gt;2. That's the overall delineation of functions. The FirePOWER functions do require licensing. AVC is included with the no-cost Control license but NGIPS, URL Filtering and Malware (AMP) are licensed features that must be purchased separately.&lt;/P&gt;
&lt;P&gt;3. Correct. (Plus you can also manage ASAs with CSM.)&lt;/P&gt;
&lt;P&gt;4. One file, one binary image package.&lt;/P&gt;
&lt;P&gt;5. Correct as of 6.0. (Note not all legacy ASA features are currently available in FTD - notably missing are all types of remote access VPN.) Stay tuned for changes to that with the release of 6.1 this summer.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 01:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862296#M167087</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-05-18T01:34:28Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862297#M167088</link>
      <description>&lt;P&gt;Thanks Marvin.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Additional Question:&lt;/P&gt;
&lt;P&gt;Assume that I have one legacy ASA (like 5525-X) without Firepower Features enabled and another ASA (like 5508-X with Firepower) with Firepower Services Module (that is pre v6.0). And now I want to migrate them to FTD and manage them with Management Center.&lt;/P&gt;
&lt;P&gt;What is the best way to&amp;nbsp;migrate objects and ACLs and other settings (ofcourse not VPN as you mentioned) ? Do I have to manually enter everything on the Management Center?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That would be a pain if you have 100s or 1000s of objects!&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 07:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862297#M167088</guid>
      <dc:creator>rjadhav163</dc:creator>
      <dc:date>2016-05-18T07:22:19Z</dc:date>
    </item>
    <item>
      <title>The best way would be to wait</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862298#M167089</link>
      <description>&lt;P&gt;The best way would be to wait until 6.1 is out in Summer 2016. There will be a standalone migration tool available then capable of migrating objects and ACLs. Over time that tool will be enhanced and integrated into FMC.&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 13:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862298#M167089</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-05-18T13:07:36Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862299#M167090</link>
      <description>&lt;P&gt;Thanks Marvin.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Unfortunately cannot wait till that long. Have to migrate the stuff next week. Is there a CLI Interface / Shell that I can use to atleast enter objects into the Management Centre.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 07:06:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862299#M167090</guid>
      <dc:creator>rjadhav163</dc:creator>
      <dc:date>2016-05-19T07:06:59Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862300#M167091</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kindly post any document over the difference of ASA with firepower &amp;amp; FTD. When to choose which one would help us to understand the product better.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 02:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862300#M167091</guid>
      <dc:creator>anil.kumark</dc:creator>
      <dc:date>2016-05-23T02:15:22Z</dc:date>
    </item>
    <item>
      <title>@rjadhav163  </title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862301#M167092</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/rjadhav163"&gt;rjadhav163&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry but there's no such capability at present.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 03:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862301#M167092</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-05-23T03:07:18Z</dc:date>
    </item>
    <item>
      <title>@anil.kumark  </title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862302#M167093</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[@anil.kumark]&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For now the respective data sheets are the best publicly available source. If you work with your partner or Cisco SE, they can assist with additional information to guide your decision making.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2016 03:08:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862302#M167093</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-05-23T03:08:45Z</dc:date>
    </item>
    <item>
      <title>Thanks Marvin however I am</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862303#M167094</link>
      <description>&lt;P&gt;Thanks Marvin however I am looking for limitations around the technical implementation of FTD and ASA here,&lt;/P&gt;
&lt;P&gt;1. Does the 4100/9300 appliance support running ASA image with firepower service as software just like the ASA X series?&lt;/P&gt;
&lt;P&gt;2. Do the 4100/9300 appliance support running ASA or FTD operation with inter &amp;amp; Intra clustering?&lt;/P&gt;
&lt;P&gt;3. Do the 4100/9300 appliance support running ASA or FTD image in HA mode (active/standby or active active) in intra and &amp;amp; inter chassis?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2016 04:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862303#M167094</guid>
      <dc:creator>anil.kumark</dc:creator>
      <dc:date>2016-05-25T04:28:32Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862304#M167095</link>
      <description>Hi,
Where you able to get the answers? I am supposed to deploy a 4110 but I need it in ASA mode so that we can run similar things as the ASA 5500X. Is this possible?</description>
      <pubDate>Wed, 14 Sep 2016 20:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862304#M167095</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2016-09-14T20:43:03Z</dc:date>
    </item>
    <item>
      <title>1. No - and never will.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862305#M167096</link>
      <description>&lt;P&gt;1. No - and never will.&lt;/P&gt;
&lt;P&gt;2. Inter-chassis clustering for ASA image only. FTD does not have clustering in any form factor..&lt;/P&gt;
&lt;P&gt;2. Inter-chassis only (at this time for 9300 - may change in the future).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 02:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862305#M167096</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-15T02:34:40Z</dc:date>
    </item>
    <item>
      <title>4110 with ASA image supports</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862306#M167097</link>
      <description>&lt;P&gt;4110 with ASA image supports all base ASA features (stateful firewall, L2L VPN,remote access VPN etc.).&lt;/P&gt;
&lt;P&gt;It does not and will not support FirePOWER module.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 02:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862306#M167097</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-09-15T02:36:00Z</dc:date>
    </item>
    <item>
      <title>Thanks for the update Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862307#M167098</link>
      <description>&lt;P&gt;Thanks for the update Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We recently upgraded FMC to 6.1 and after upgrading we face issues with AMP cloud. When we go to AMP Management page (&lt;SPAN&gt;&lt;SPAN class="menucascade"&gt;&lt;SPAN class="uicontrol"&gt;AMP&lt;/SPAN&gt; &amp;gt; &lt;SPAN class="uicontrol"&gt;AMP Management&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;) we don't see the default US site listed there. When we try to create a FMC connection then system does not pull any site information instead it displace "None".&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Attached the screen shot, we did verify that DNS and its working fine.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2016 07:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862307#M167098</guid>
      <dc:creator>anil.kumark</dc:creator>
      <dc:date>2016-10-24T07:56:09Z</dc:date>
    </item>
    <item>
      <title>@anil.kumark  ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862308#M167099</link>
      <description>&lt;P&gt;&lt;SPAN&gt;[@anil.kumark]&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;I haven't seen that one. My FMC 6.1 retained its connection to the US Cloud.&lt;/P&gt;
&lt;P&gt;I'd open a TAC case on that one.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 02:23:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862308#M167099</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-10-25T02:23:40Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862309#M167100</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a question of the ASA 5516-X FTD, I want to reimage this device with an ASA IOS, because the costumer want to have the ASA conifguration via CLI. My doubt was, if I reimage this ASA with ASA IOS can I deploy the sfr module and integrate with Firepower Management Center? or we lose the module with capabilities Firepower as you mentioned with the appliance 4110?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 22:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862309#M167100</guid>
      <dc:creator>bernardovr</dc:creator>
      <dc:date>2017-08-15T22:59:55Z</dc:date>
    </item>
    <item>
      <title>@bernardovr  ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862310#M167101</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/bernardovr"&gt;bernardovr&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;When you reimage an ASA with FTD to ASA image type, you have a "regular" ASA capable of running the Firepower service module.&lt;/P&gt;
&lt;P&gt;Note the license types for FTD vs. Firepower service are different so the device would have to be relicensed for Firepower services. There is no "migration license" or such.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 02:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862310#M167101</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-16T02:25:30Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin, </title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862311#M167102</link>
      <description>&lt;P&gt;Hi Marvin,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the answer, one question more the relicense has no cost? Or the costumer must buy the license.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 16:05:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862311#M167102</guid>
      <dc:creator>bernardovr</dc:creator>
      <dc:date>2017-08-17T16:05:30Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862312#M167103</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;They are different license SKUs with different costs. The new image would need newly purchased licenses. If it is a significant deal size, you may want to speak with the account manager from Cisco for potential relief on the cost.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 16:08:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/2862312#M167103</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-17T16:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: The best way would be to wait</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/3225403#M167104</link>
      <description />
      <pubDate>Fri, 01 Dec 2017 03:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/3225403#M167104</guid>
      <dc:creator>Shaaka</dc:creator>
      <dc:date>2017-12-01T03:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Thanks Marvin.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/3225404#M167105</link>
      <description>&lt;P&gt;Thanks for your updates, those are really helpful.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a question on migrating from asa firepower module to frd, is any additional licenses required or existing licenses are enough. As we have url,mulware,avc,ngips and GMC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 03:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-ftd-vs-firepower-software/m-p/3225404#M167105</guid>
      <dc:creator>Shaaka</dc:creator>
      <dc:date>2017-12-01T03:10:31Z</dc:date>
    </item>
  </channel>
</rss>

