08-31-2016 02:23 PM - edited 02-20-2020 09:01 PM
By reading the FirePOWER documentation and by looking at Cisco Live slides (see uploaded slide), it seems that files are submitted for dynamic analysis by the ASA-SFR directly for dynamic analysis.
Could the files be submitted for dynamic analysis by FMC 6.0 instead of SFR?
Thanks,
Cath.
Solved! Go to Solution.
09-07-2016 12:42 PM
Hey Cath,
Dynamic analysis capable files are sent by the sensor to the cloud for analysis. The sensor in your deployment is the SFR module on the ASA. The way that dynamic analysis is designed, the file is only sent from the SFR module. There is no configuration that allows you to send file from the FMC for dynamic analysis. The file is intercepted at the sensor (SFR Module), not the FMC, so we have to send the file from the sensor to be analyzed. I hope this addresses your question adequately. Have a nice day!
Regards,
Matt J
FireAMP Engineer @Cisco
09-02-2016 12:22 AM
Hello Team,
For dynamic analysis, files are never sent from FMC and thus its not possible to use it instead of SFR.
Rate and mark correct if the post helps you.
Regards
Jetsy
09-06-2016 10:49 PM
Hello Team,
Is your queries clear ?
If so , please rate and mark correct if the post helps you.
Regards
Jetsy
09-07-2016 12:40 PM
Hey Cath,
Dynamic analysis capable files are sent by the sensor to the cloud for analysis. The sensor in your deployment is the SFR module on the ASA. The way that dynamic analysis is designed, the file is only sent from the SFR module. There is no configuration that allows you to send file from the FMC for dynamic analysis. The file is intercepted at the sensor (SFR Module), not the FMC, so we have to send the file from the sensor to be analyzed. I hope this addresses your question adequately. Have a nice day!
Regards,
Matt J
FireAMP Engineer @Cisco
09-07-2016 12:42 PM
Hey Cath,
Dynamic analysis capable files are sent by the sensor to the cloud for analysis. The sensor in your deployment is the SFR module on the ASA. The way that dynamic analysis is designed, the file is only sent from the SFR module. There is no configuration that allows you to send file from the FMC for dynamic analysis. The file is intercepted at the sensor (SFR Module), not the FMC, so we have to send the file from the sensor to be analyzed. I hope this addresses your question adequately. Have a nice day!
Regards,
Matt J
FireAMP Engineer @Cisco
03-25-2019 08:00 AM
what if you are dealing with sensitive documents? would dynamic analysis upload those sensitive documents to the cloud for analysis?
09-13-2016 06:52 AM
Hello Team,
Is your queries are clear now ?
Regards
Jetsy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide