<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic You are best qualified to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902864#M43800</link>
    <description>&lt;P&gt;You are best qualified to decide what works best in your environment.&lt;/P&gt;
&lt;P&gt;Cisco's security products are backed by the best (&lt;SPAN&gt;by an order of magnitude&lt;/SPAN&gt;) and most comprehensive security research orgainization in the world (Talos).&lt;/P&gt;
&lt;P&gt;Most other vendors are just playing catch-up or selling to their installed base. Checkpoint Threatcloud doesn't even come close to Talos.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2017 15:44:49 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-07-17T15:44:49Z</dc:date>
    <item>
      <title>Cisco Firewall in AWS - Should i use ASAv or FTDv/FMCv?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902859#M43791</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to setup a DMZ for my client in AWS. I've never done this before and hence the question. I'm planning to use ASAv as the Internet Facing firewall and FTDv/FMCv (Firepower threat Detection virtual and Firepower Management Center virtual) for Threat Detection.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've been told that i could instead just use the FTDv/FMCv instead of using an ASAv as it works as a Firewall as well (Next Generation Firewall - NGFW).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could someone please advise if this is indeed the case? If that is the case, then is it a whole different than the ASA (as a firewall)? I'm quite familiar with the ASA, but not the Firepower and I have some tight timelines to meet for this project, so was wondering if the Firepower NGFW is similar in configuration as a firewall as for an ASA?&lt;/P&gt;
&lt;P&gt;Also, when i take a look at the licensing/part numbers for the ASAv, i see this terminology which says : 16 pack and 8 pack licenses. What does this mean? Does this mean that i can use this one license for 16 or 8 ASAvs?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;Ramesh&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:21:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902859#M43791</guid>
      <dc:creator>Ramesh.Ramani</dc:creator>
      <dc:date>2019-03-26T00:21:40Z</dc:date>
    </item>
    <item>
      <title>As of right now, which you</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902860#M43792</link>
      <description>&lt;P&gt;As of right now, which you choose depends on what features you need.&lt;/P&gt;
&lt;P&gt;ASAv has almost all of the classic ASA appliance features. i.e. &amp;nbsp;it's a stateful firewall in virtual appliance form factor.&lt;/P&gt;
&lt;P&gt;FTDv/FMCv is more of an IPS solution (although 6.1 due out in the next month will up the game (still short of feature parity) vis a vis what an ASA offers).&lt;/P&gt;
&lt;P&gt;The ASAv licenses are indeed offered only for multiples at this time. 16- and 8-pack are just that.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2016 00:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902860#M43792</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-07-08T00:00:58Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902861#M43793</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;please tell me if we can get SourceFire&amp;nbsp;features with ASAv or is a hardware appliance necessary?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_116 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar multiReplace" id="116" data-gr-id="116"&gt;Customer&lt;/G&gt; is also asking if these features &lt;G class="gr_ gr_117 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar multiReplace" id="117" data-gr-id="117"&gt;are support&lt;/G&gt;:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- SSL inspection&lt;/P&gt;
&lt;P&gt;- BW control&lt;/P&gt;
&lt;P&gt;- Inline Malware protection&lt;/P&gt;
&lt;P&gt;- Anti SPAM&lt;/P&gt;
&lt;P&gt;- IPS (probably part of SFire)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 08:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902861#M43793</guid>
      <dc:creator>smailmilak</dc:creator>
      <dc:date>2017-07-17T08:42:38Z</dc:date>
    </item>
    <item>
      <title>ASAv is ASA only - no</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902862#M43795</link>
      <description>&lt;P&gt;ASAv is ASA only - no Firepower features at all.&lt;/P&gt;
&lt;P&gt;FTD is available in virtual machine (VM) form. I have never seen anybody try to do SSL inspection on that although technically it is possible. The performance goes down considerably (75%+).&lt;/P&gt;
&lt;P&gt;Basic bandwidh control is possible with FTD, as is inline Malware and IPS.&lt;/P&gt;
&lt;P&gt;Antispam is more of an email security appliance (ESA) feature.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 12:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902862#M43795</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-17T12:16:08Z</dc:date>
    </item>
    <item>
      <title>Thanks!</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902863#M43797</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So we should go with &lt;G class="gr_ gr_25 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="25" data-gr-id="25"&gt;FTDv&lt;/G&gt;?&lt;BR /&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/vmware/ftdv/ftdv-vmware-qsg.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It seems that those requirements are more for Checkpoint?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 12:41:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902863#M43797</guid>
      <dc:creator>smailmilak</dc:creator>
      <dc:date>2017-07-17T12:41:45Z</dc:date>
    </item>
    <item>
      <title>You are best qualified to</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902864#M43800</link>
      <description>&lt;P&gt;You are best qualified to decide what works best in your environment.&lt;/P&gt;
&lt;P&gt;Cisco's security products are backed by the best (&lt;SPAN&gt;by an order of magnitude&lt;/SPAN&gt;) and most comprehensive security research orgainization in the world (Talos).&lt;/P&gt;
&lt;P&gt;Most other vendors are just playing catch-up or selling to their installed base. Checkpoint Threatcloud doesn't even come close to Talos.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 15:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902864#M43800</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-17T15:44:49Z</dc:date>
    </item>
    <item>
      <title>Thanks for the tip.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902865#M43803</link>
      <description>&lt;P&gt;Thanks for the tip.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So SSL inspection and BW control is a feature on WSA?&lt;/P&gt;
&lt;P&gt;Antispam is a feature on ESA like you have said. The other features are supported on &lt;G class="gr_ gr_149 gr-alert gr_spell gr_inline_cards gr_disable_anim_appear ContextualSpelling ins-del multiReplace" id="149" data-gr-id="149"&gt;vFTD&lt;/G&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 06:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902865#M43803</guid>
      <dc:creator>smailmilak</dc:creator>
      <dc:date>2017-07-18T06:36:43Z</dc:date>
    </item>
    <item>
      <title>Yes the WSA does both SSL</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902866#M43806</link>
      <description>&lt;P&gt;Yes the WSA does both SSL inspection and bandwidth control.&lt;/P&gt;
&lt;P&gt;While it can be done technically for many sites, most organizations do not opt for SSL inspection of otbound traffic as it is very resource intensive, requires an enterprise PKI and potentially presents privacy concerns. Also some applications use certificate pinning and&amp;nbsp;other technologies that thwart any scheme that uses man-in-the-middle decryption/re-encryption.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 15:41:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firewall-in-aws-should-i-use-asav-or-ftdv-fmcv/m-p/2902866#M43806</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-18T15:41:48Z</dc:date>
    </item>
  </channel>
</rss>

