<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FPS vs FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fps-vs-ftd/m-p/3361318#M963402</link>
    <description>&lt;P&gt;Is the main difference between FPS and FTD that with FTD as far as management of the ASA goes that object/ACE creation will need to be done from the FMC itself and not possible through an ASDM or CLI? Is it the goal of Cisco to eliminate IOS/CLI access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has been awhile for me since I worked within firepower and FTD at that time was spoken of but not quite there yet for production deployments. What is the current status of FTD and obviously as asked above is my perceivement wrong?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:36:13 GMT</pubDate>
    <dc:creator>keithcclark71</dc:creator>
    <dc:date>2020-02-21T15:36:13Z</dc:date>
    <item>
      <title>FPS vs FTD</title>
      <link>https://community.cisco.com/t5/network-security/fps-vs-ftd/m-p/3361318#M963402</link>
      <description>&lt;P&gt;Is the main difference between FPS and FTD that with FTD as far as management of the ASA goes that object/ACE creation will need to be done from the FMC itself and not possible through an ASDM or CLI? Is it the goal of Cisco to eliminate IOS/CLI access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It has been awhile for me since I worked within firepower and FTD at that time was spoken of but not quite there yet for production deployments. What is the current status of FTD and obviously as asked above is my perceivement wrong?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-vs-ftd/m-p/3361318#M963402</guid>
      <dc:creator>keithcclark71</dc:creator>
      <dc:date>2020-02-21T15:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: FPS vs FTD</title>
      <link>https://community.cisco.com/t5/network-security/fps-vs-ftd/m-p/3362340#M963403</link>
      <description>&lt;P&gt;It's a bit more than the management. FTD basically combines the asa and sourcefire code into one image so there is no need for a software or hardware module in the firewall. I wouldn't say it is their goal to eliminate CLI but it was an unfortunate conclusion that was reached. CLI configuration is not possible as of now (with some cli operations being the exception) and all configuration must be done from FMC or FDM UI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As of now I would say it is worth taking a look at, since it will be the way forward in ciscos firewall strategy. Ofc there are still some limitations that you should keep in mind:&lt;/P&gt;
&lt;H2 id="unsupported"&gt;Unsupported&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Multiple-Context mode&lt;/LI&gt;
&lt;LI&gt;Clientless SSL VPN&lt;/LI&gt;
&lt;LI&gt;Configuration CLI&lt;/LI&gt;
&lt;LI&gt;HA (Active/Standby) for Public Cloud (AWS/Azure)&lt;/LI&gt;
&lt;LI&gt;ASA5585-X Platform support (not possible due to hardware architecture)&lt;/LI&gt;
&lt;LI&gt;Hyper-V support&lt;/LI&gt;
&lt;LI&gt;TLS Proxy for Encrypted Voice Inspection&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 id="supported-with-limitations"&gt;Supported with limitations&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Local device manager (no feature parity between FDM and FMC)&lt;/LI&gt;
&lt;LI&gt;Central management via in-band data path (Staging or OOB required for remote management)&lt;/LI&gt;
&lt;LI&gt;AnyConnect (no feature parity with ASA)&lt;/LI&gt;
&lt;LI&gt;REST API (no feature parity with ASA REST API yet)&lt;/LI&gt;
&lt;LI&gt;SSL Acceleration (only for FPR4100 &amp;amp; FPR9300)&lt;/LI&gt;
&lt;LI&gt;Clustering (only for FPR4100 &amp;amp; FPR9300)&lt;/LI&gt;
&lt;LI&gt;Unified Connection Logging (FTD Connection events do not include detailed L4 information, e.g. SYN Timeout, etc.)&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 id="supported-with-flexconfig"&gt;Supported with FlexConfig&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Modular Policy Framework (e.g. changing tcp timeouts, changing inspections depending on ACL)&lt;/LI&gt;
&lt;LI&gt;Bidirectional Forwarding Detection (BFD)&lt;/LI&gt;
&lt;LI&gt;Web Cache Communications Protocol (WCCP)&lt;/LI&gt;
&lt;LI&gt;Virtual Extensible LAN (VXLAN)&lt;/LI&gt;
&lt;LI&gt;Intermediate System to Intermediate System (IS-IS)&lt;/LI&gt;
&lt;LI&gt;Enhanced Interior Gateway Routing Protocol (EIGRP)&lt;/LI&gt;
&lt;LI&gt;Policy-based Routing (PBR)&lt;/LI&gt;
&lt;LI&gt;Equal-cost multi-path routing (ECMP)&lt;/LI&gt;
&lt;LI&gt;NetFlow&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Apr 2018 09:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-vs-ftd/m-p/3362340#M963403</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2018-04-08T09:37:15Z</dc:date>
    </item>
  </channel>
</rss>

