We are going to upgrade the ASA5515 to FPR-ASA-1120,i am confused about the difference between FPR-NGFW-1120 and FPR-ASA-1120,i want konw how to choose the model according to the specific request.
my current request is ssl-vpn function,so i think it is enough for me to choose the FPR-ASA Serials,and FPR-NGFW Serials are normally used at the network edge(boundary),am i right?
i hope you can explain it to me in details.
thank you!
duan
Hello jh.duan,
you can find similar kind of discussion here....hope might be helpful....
Best regards
******* If This Helps, Please Rate *******
NGFW提供了比传统ASA更强大的网络防护功能,能做基于应用的识别和控制,相对来说更符合防火墙的理解。
NGFW和ASA的两种型号都可以配置remote access vpn,只是配置方法上稍有差异罢了,使用上不会有太大的差异,不过如果从asa过渡到FPR-ASA相对来说比较容易,命令行基本上是一致的,只是不同版本上会有一些特性支持的差异。
另外需要注意的一点,在asa551x平台上的授权是永久授权,FPR上的是使用smart license的订阅的授权
有更详细的需求可以直接给思科的400打电话,直接报相关的需求,思科那边应该会给出更详细全面的解答
产品参数可以查对应的datasheet,配置文档找configuration guide
firepower 1000 datasheet:https://www.cisco.com/c/en/us/products/collateral/security/firepower-1000-series/datasheet-c78-742469.html
configuration guide firepower fdm : https://www.cisco.com/c/en/us/td/docs/security/firepower/720/fdm/fptd-fdm-config-guide-720/fptd-fdm-identity-sources.html#id_72527