<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 2110 management and deployment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386041#M957377</link>
    <description>&lt;P&gt;Dear,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently purchased two Firepower 2110 with threat, malware and URL license. Below is the BoQ of the new hardware&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Firepower 2110 Master Bundle&lt;BR /&gt;Cisco Firepower 2110 ASA Appliance, 1U&lt;BR /&gt;SNTC-8X5XNBD Cisco Firepower 2110 ASA Appliance, 1U&lt;BR /&gt;AC Power Cord (UK), C13, BS 1363, 2.5m&lt;BR /&gt;Cisco ASA 9.8 Software for Firepower 2100 appliance series&lt;BR /&gt;Cisco Firepower 2100 - Add 5 Security Context Licenses&lt;BR /&gt;Firepower 2000 Series SSD for FPR-2110/2120&lt;BR /&gt;Cisco Firepower 2100 Standard ASA License&lt;BR /&gt;Firepower 2000 Series SSD Slot Carrier&lt;BR /&gt;Cisco FPR2110 Threat Defense Threat, Malware and URL License&lt;BR /&gt;Cisco FPR2110 Threat Defense Threat, Malware and URL 1Y Subs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will be using it as a perimeter firewall with multiple security context, HA&amp;nbsp;and IPsec VPN, Anyconnect VPN, URL filtering, AMP, IPS etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, we currently do not have FMC license to make these units as HA and to configure security context as the on-box management FDM doesn't support configuring HA and security context. Kindly suggest if FMC is mandatory to configure HA and security context?&lt;/P&gt;
&lt;P&gt;Also, we need to deploy this Firepower units as NGFW or NGIPS to achieve the above requirements? and what is the difference between using Firepower as NGFW or NGIPS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Omer&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:47:27 GMT</pubDate>
    <dc:creator>omer14231</dc:creator>
    <dc:date>2020-02-21T15:47:27Z</dc:date>
    <item>
      <title>Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386041#M957377</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have recently purchased two Firepower 2110 with threat, malware and URL license. Below is the BoQ of the new hardware&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Firepower 2110 Master Bundle&lt;BR /&gt;Cisco Firepower 2110 ASA Appliance, 1U&lt;BR /&gt;SNTC-8X5XNBD Cisco Firepower 2110 ASA Appliance, 1U&lt;BR /&gt;AC Power Cord (UK), C13, BS 1363, 2.5m&lt;BR /&gt;Cisco ASA 9.8 Software for Firepower 2100 appliance series&lt;BR /&gt;Cisco Firepower 2100 - Add 5 Security Context Licenses&lt;BR /&gt;Firepower 2000 Series SSD for FPR-2110/2120&lt;BR /&gt;Cisco Firepower 2100 Standard ASA License&lt;BR /&gt;Firepower 2000 Series SSD Slot Carrier&lt;BR /&gt;Cisco FPR2110 Threat Defense Threat, Malware and URL License&lt;BR /&gt;Cisco FPR2110 Threat Defense Threat, Malware and URL 1Y Subs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We will be using it as a perimeter firewall with multiple security context, HA&amp;nbsp;and IPsec VPN, Anyconnect VPN, URL filtering, AMP, IPS etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, we currently do not have FMC license to make these units as HA and to configure security context as the on-box management FDM doesn't support configuring HA and security context. Kindly suggest if FMC is mandatory to configure HA and security context?&lt;/P&gt;
&lt;P&gt;Also, we need to deploy this Firepower units as NGFW or NGIPS to achieve the above requirements? and what is the difference between using Firepower as NGFW or NGIPS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Omer&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386041#M957377</guid>
      <dc:creator>omer14231</dc:creator>
      <dc:date>2020-02-21T15:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386072#M957380</link>
      <description>&lt;P&gt;Somebody advised you incorrectly with that bill of materials. A Firepower 2110 (or any 2100, 5100 or 9300 series Firepower appliance) can run either ASA logical device(s) or FTD logical device(s). That is, NGFW or NGIPS in marketing terms.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you run an NGFW you get all the ASA features like multi-context, AnyConnect remote access VPN without feature restriction, etc. You do NOT get IPS, URL filtering, and Malware protection. So buying the license for those features on an NGFW is not only unnecessary but also something you will not be able to use at all. Also, you configure the ASA HA pair and their contexts using the traditional ASA methods (cli, ASDM etc.) - NOT FMC. You use FDM deploy the ASA logical devices on the chassis and assign interfaces to it, but once that's done everything else looks 98% like a classic ASA appliance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you run an NGIPS you get the integrated FTD image (not all ASA features - most definitely no multi-context and limited AnyConnect features). the following two line items in your list apply ONLY to NGIPS deployments:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cisco FPR2110 Threat Defense Threat, Malware and URL License&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Cisco FPR2110 Threat Defense Threat, Malware and URL 1Y Subs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 13:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386072#M957380</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-20T13:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386077#M957383</link>
      <description>Marvin - how come you know so much about this FTD appliances; you work for Cisco after all?</description>
      <pubDate>Sun, 20 May 2018 13:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386077#M957383</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-05-20T13:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386083#M957464</link>
      <description>&lt;P&gt;I am an independent engineer but do work for a couple of partners. Since I do both pre-sales and post-sales (deployment), I do my best to keep very up to date on all things Cisco security.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since I've been working with security one way or another for about 35 years and Cisco for 25 years, I pretty much have the basics (and a few of the more advanced topics) figured out by now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate my earlier reply if it answered your questions.&lt;/P&gt;</description>
      <pubDate>Sun, 20 May 2018 14:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386083#M957464</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-20T14:29:11Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386276#M957543</link>
      <description>Hi Marvin Rhoads,&lt;BR /&gt;&lt;BR /&gt;Thanks a lot for the detailed explanation . &lt;BR /&gt;&lt;BR /&gt;But one thing can you please explain . If we want both features ( NGFW +&lt;BR /&gt;NGIPS ) like what we use to do with ASA 5585-X by adding sensor to FMC to&lt;BR /&gt;utilize both features. So with Firepower 2110 we need to buy two hardware's&lt;BR /&gt;for NGFW + NGIPS ? If we use Firepower 2110 as NGFW then we will able to&lt;BR /&gt;manage by FDM but we cannot configure security context and HA by using FDM ?&lt;BR /&gt;</description>
      <pubDate>Mon, 21 May 2018 07:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386276#M957543</guid>
      <dc:creator>omer14231</dc:creator>
      <dc:date>2018-05-21T07:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386281#M957545</link>
      <description>&lt;P&gt;You're welcome&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/595321"&gt;@omer14231&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Until the multi-instance support comes out in FTD, Cisco has been encouraging customers to look at alternatives such as the 2-appliance (or 2 pairs of appliances) solutions such as you mention or possibly re-examining the design to see if an alternative such as zones might meet your requirements. By the way, the 2100 series may not ever have multi-instance support due to its hardware design.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When a 2100 series is running ASA image you only manage the chassis with FDM. All the NGFW features and configuration is done just as if is was a classic ASA.&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 07:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386281#M957545</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-21T07:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386286#M957546</link>
      <description>Thanks Marven.&lt;BR /&gt;&lt;BR /&gt;So from FDM we can configure High Availability ?&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Mon, 21 May 2018 07:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386286#M957546</guid>
      <dc:creator>omer14231</dc:creator>
      <dc:date>2018-05-21T07:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386297#M957547</link>
      <description>&lt;P&gt;No. FDM cannot currently be used to configure NGIPS (FTD image) HA (as of release 6.2.3). We expect that will be added in 6.3 (ca. Fall 2018). In the interim you would need to use FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;NGFW (ASA image) HA is configured, even on Firepower appliance, via ASA cli or ASDM, just like on ASA appliance.&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 08:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386297#M957547</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-21T08:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386311#M957548</link>
      <description>Thank you Marvin.&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;One last thing can you please what limitations for cisco anyconnect when&lt;BR /&gt;running FTD image . Can you please share with me the link of datasheet for&lt;BR /&gt;fire power.&lt;BR /&gt;</description>
      <pubDate>Mon, 21 May 2018 09:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386311#M957548</guid>
      <dc:creator>omer14231</dc:creator>
      <dc:date>2018-05-21T09:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 management and deployment</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386352#M957549</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AnyConnect limitations for FTD (as of the latest 6.2.3):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/firepower_threat_defense_remote_access_vpns.html#reference_xby_dml_wy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623/firepower_threat_defense_remote_access_vpns.html#reference_xby_dml_wy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data sheet:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw/datasheet-c78-736661.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw/datasheet-c78-736661.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 11:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-management-and-deployment/m-p/3386352#M957549</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-21T11:45:19Z</dc:date>
    </item>
  </channel>
</rss>

