<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic asa 5506 with sourcefire  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629800#M18456</link>
    <description>&lt;P&gt;hi out there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get most out of a 5506 with sourcefire - I direct trough the default global ploicy *any* traffic trough the sfr module.&lt;/P&gt;&lt;P&gt;I can also verify that it Works by f.ex defining a facebook free Network which would block facebook. - and this Works fine.&lt;/P&gt;&lt;P&gt;But I would like to get some reports what it does and here I am a bit lost.&lt;/P&gt;&lt;P&gt;When I trough the ASDM go to monitoring -&amp;gt; ASA firepower monitoring -&amp;gt; real time eventing I get nothing listed? Even though there is a lot of traffic to inspect and on the ASDM log on the home page in the ASDM syslog window&amp;nbsp;I can also see that ASDM logs a lot of sessions where the sfr module requests the asa to bypass further packet redirection and process UDP/TCP flow&lt;/P&gt;&lt;P&gt;But when I open the firepower dashboard or firepower reporting no data is avalibly ??&lt;/P&gt;&lt;P&gt;Ehhh - is there either some which can give me some tips - completely new to sourcefire - or tell me what I have done wrong ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br /tiwang&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2015 20:24:52 GMT</pubDate>
    <dc:creator>tiwang</dc:creator>
    <dc:date>2015-04-21T20:24:52Z</dc:date>
    <item>
      <title>asa 5506 with sourcefire</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629800#M18456</link>
      <description>&lt;P&gt;hi out there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get most out of a 5506 with sourcefire - I direct trough the default global ploicy *any* traffic trough the sfr module.&lt;/P&gt;&lt;P&gt;I can also verify that it Works by f.ex defining a facebook free Network which would block facebook. - and this Works fine.&lt;/P&gt;&lt;P&gt;But I would like to get some reports what it does and here I am a bit lost.&lt;/P&gt;&lt;P&gt;When I trough the ASDM go to monitoring -&amp;gt; ASA firepower monitoring -&amp;gt; real time eventing I get nothing listed? Even though there is a lot of traffic to inspect and on the ASDM log on the home page in the ASDM syslog window&amp;nbsp;I can also see that ASDM logs a lot of sessions where the sfr module requests the asa to bypass further packet redirection and process UDP/TCP flow&lt;/P&gt;&lt;P&gt;But when I open the firepower dashboard or firepower reporting no data is avalibly ??&lt;/P&gt;&lt;P&gt;Ehhh - is there either some which can give me some tips - completely new to sourcefire - or tell me what I have done wrong ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;br /tiwang&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2015 20:24:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629800#M18456</guid>
      <dc:creator>tiwang</dc:creator>
      <dc:date>2015-04-21T20:24:52Z</dc:date>
    </item>
    <item>
      <title>I have the same observations.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629801#M18458</link>
      <description>&lt;P&gt;I have the same observations. But have been unable to find information on getting the reporting to work, in particular, the Firepower Dashboards.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 21:09:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629801#M18458</guid>
      <dc:creator>thomas.talley</dc:creator>
      <dc:date>2015-05-05T21:09:44Z</dc:date>
    </item>
    <item>
      <title>Make sure you have a "Monitor</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629802#M18461</link>
      <description>&lt;P&gt;Make sure you have a "Monitor All" rule in your Access Control Policy.&lt;/P&gt;&lt;P&gt;Add a rule and set the Action to "Monitor", leave all the other fields default.&lt;/P&gt;&lt;P&gt;In my case I already had this rule in place day one and real time eventing just stopped working. I ended up moving the rule to Administrator Rules and applying/saving the policy.&lt;/P&gt;&lt;P&gt;On the most current release the ASA 5506 with Firepower is simply buggy.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2015 03:26:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-with-sourcefire/m-p/2629802#M18461</guid>
      <dc:creator>ED CRAIG</dc:creator>
      <dc:date>2015-06-23T03:26:58Z</dc:date>
    </item>
  </channel>
</rss>

