<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic thanks again Marvin. i am in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808503#M44337</link>
    <description>&lt;P&gt;thanks again Marvin. i am able to get further this time following your guide. i am having a separate issue now after i connect to the sfr console. i am not able to ping the gateway. i need to troubleshoot it further but the guidance you provided atleast allowed me to load the boot image so far.&lt;/P&gt;
&lt;P&gt;i will try to figure out why i can't ping the gateway from sfr console.&lt;/P&gt;
&lt;P&gt;i will mark your answer as correct answer.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks again for your help.&lt;/P&gt;</description>
    <pubDate>Sun, 20 Dec 2015 23:54:04 GMT</pubDate>
    <dc:creator>The Learned</dc:creator>
    <dc:date>2015-12-20T23:54:04Z</dc:date>
    <item>
      <title>Installing Firepower on redundant ASA 5512x pair</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808499#M44333</link>
      <description>&lt;P&gt;Hi, I am trying to install firepower on redundant asa5512x pair that are configured in active/standby mode. these asas have an IPS module installed. I need to remove the old IPS module and install the firepower module.&lt;/P&gt;
&lt;P&gt;I know that I need to shutdown the existing ips module, uninstall it then load the firepower boot image etc... however, I have no experience working with redundant units so I am not sure how to go about installing firepower in active/standby configuration.&lt;/P&gt;
&lt;P&gt;I have searched for guides/instructions on how to do this ips upgrade in redundant asa pair&amp;nbsp;but the only guides I have found so far talk about upgrading to firepower in standalone asa unit.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;any suggestions, instructions or links to blog/sites that provide step by step instruction on upgrading to firepower in active/standy mode would be much appreciated.&lt;/P&gt;
&lt;P&gt;thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808499#M44333</guid>
      <dc:creator>The Learned</dc:creator>
      <dc:date>2019-03-10T13:31:42Z</dc:date>
    </item>
    <item>
      <title>The FirePOWER modules</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808500#M44334</link>
      <description>&lt;P&gt;The FirePOWER modules themselves are completely unaware of the ASAs being in Active/Standby (or any other HA or clustering setup). There is no synchronization directly between the modules.&amp;nbsp;As such, you setup each one independently.&lt;/P&gt;
&lt;P&gt;You can configure and manage them from ASDM (as of ASA 9.5(2) and FirePOWER 6.0) or from an external FireSIGHT / FirePOWER Management Center. The latter method allows you to create policies once and deploy to any number of managed modules (as long as you have the necessary licenses).&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2015 14:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808500#M44334</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-19T14:21:17Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin thank you for your</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808501#M44335</link>
      <description>&lt;P&gt;Hi Marvin thank you for your response. i use asa 9.2.2(4). i was trying to shutdown/uninstall the existing ips module (tried it first on standby asa and that didn't work so tried on active as well) but in both cases, it looks like ASA reboots after running the uninstall ips command and the standby unit becomes active. when the unit that rebooted comes back up, it gets configuration from newly active asa so nothing changes.its like i rebooted the asa for nothing. and since i can't install firepower without uninstalling the existing ips first, i am stuck.&lt;/P&gt;
&lt;P&gt;i guess i am looking for step by step instructions on how i can uninstall the existing ips modules in failover configuration (while minimizing downtime). after that, like you said, i need to individually install the firepower module on both active and standby unit and manage them using firesight.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2015 16:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808501#M44335</guid>
      <dc:creator>The Learned</dc:creator>
      <dc:date>2015-12-19T16:01:26Z</dc:date>
    </item>
    <item>
      <title>Do I understand you to say</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808502#M44336</link>
      <description>&lt;P&gt;Do I understand you to say that the module ips uninstall causes failover? That should be ok because in ASA 9.2.x and earlier the HA pair monitors the service module status by default and that cannot be disabled.&lt;/P&gt;
&lt;P&gt;ASA 9.3 introduced&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;(no) monitor-interface service-module&lt;/PRE&gt;
&lt;P&gt;...which allows you to disable that behavior.&lt;/P&gt;
&lt;P&gt;Even on 9.2.x though, you should be able to do the uninstall on the standby unit. When you say it didn't work, what error did you get?&lt;/P&gt;
&lt;P&gt;The order I would suggest is:&lt;/P&gt;
&lt;P&gt;1. Uninstall ips on secondary-standby. Primary-active should see module go down and mark mate not ready.&lt;/P&gt;
&lt;P&gt;2. Repeat on primary-active. When the primary-active unit reloads, the secondary-standby should see no active mate and assume active role. You should now have that situation of secondary-active and primary-standby&lt;/P&gt;
&lt;P&gt;3. Install sfr on primary-standby. Load boot image, perform initial module setup and load running image.&lt;/P&gt;
&lt;P&gt;4. Install sfr on secondary-active, including load and setup steps. When primary-standby sees the secondary-active reload, it should assume active state and be primary-active. After secondary-standby reloads it should have matching module type (i.e both have sfr installed).&lt;/P&gt;
&lt;P&gt;5. Register and verify connection to FireSIGHT Management Center on both sfr modules.&lt;/P&gt;
&lt;P&gt;6. Create and deploy policies to both ASAs' modules.&lt;/P&gt;
&lt;P&gt;7. Modify ASA service-policy to redirect traffic to the sfr module for inspection per the deployed policies on those modules.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2015 18:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808502#M44336</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-19T18:42:15Z</dc:date>
    </item>
    <item>
      <title>thanks again Marvin. i am</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808503#M44337</link>
      <description>&lt;P&gt;thanks again Marvin. i am able to get further this time following your guide. i am having a separate issue now after i connect to the sfr console. i am not able to ping the gateway. i need to troubleshoot it further but the guidance you provided atleast allowed me to load the boot image so far.&lt;/P&gt;
&lt;P&gt;i will try to figure out why i can't ping the gateway from sfr console.&lt;/P&gt;
&lt;P&gt;i will mark your answer as correct answer.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks again for your help.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Dec 2015 23:54:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808503#M44337</guid>
      <dc:creator>The Learned</dc:creator>
      <dc:date>2015-12-20T23:54:04Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808504#M44338</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Can you share a sketch or describe how your network is setup?&lt;/P&gt;
&lt;P&gt;Have you followed the Quick Start Guide (and setup the sfr module considering that the ASA physical management interface MUST be used for the sfr module and is only optional for the ASA itself)?&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html&lt;/P&gt;
&lt;P&gt;Can you tell us the output of "show run interface m0/0" from the ASA?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Dec 2015 04:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808504#M44338</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-21T04:22:52Z</dc:date>
    </item>
    <item>
      <title>i think that is the problem.</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808505#M44339</link>
      <description>&lt;P&gt;i think that is the problem. in our setup, management and data networks are separate and dont talk to each other. i will move firesight vm to the management network and it should work.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 04:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808505#M44339</guid>
      <dc:creator>The Learned</dc:creator>
      <dc:date>2015-12-23T04:45:14Z</dc:date>
    </item>
    <item>
      <title>That will do it.</title>
      <link>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808506#M44340</link>
      <description>&lt;P&gt;That will do it.&lt;/P&gt;
&lt;P&gt;The FireSIGHT Management Center most definitely needs to be able to reach the FirePOWER module. That module can &lt;STRONG&gt;only&lt;/STRONG&gt; communicate the ASA's physical m0/0 interface.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 04:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/installing-firepower-on-redundant-asa-5512x-pair/m-p/2808506#M44340</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-23T04:50:54Z</dc:date>
    </item>
  </channel>
</rss>

