cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
40662
Views
55
Helpful
58
Replies

ASA FirePOWER Threat Defense unified image (FTD)

ilukeberry
Level 1
Level 1

Hi

Can someone from Cisco please explain what this image is? And what parts of ASA does include ? Can it do VPN/Anyconnect ?

Is ASA OS getting retired ?

Regards

58 Replies 58

Hello Marvin,

we have an ASA 5515-X with Security Plus license, but without Firepower. After successfully flashing the ftd-boot-9.6.2.0.cdisk, the installtion of ftd-6.2.0-362.pkg failed with a "disk not found" during setup.

1.) So I guess FTD requieres an SSD, is that right?
2.) Are further Hardware modules required for FTD?

3.) Also I would like to know if I can use the "normal" ASA license Features (well, those that are already implemented of course) without registering for Smart Licensing.

admtkorte  ,

Yes - both FTD and ASA FirePOWER service module images require the SSD.

It's not explicitly called out in the documentation for reimaging the ASA with FTD:

http://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/reimage/asa-ftd-reimage.html#pgfId-129933

...but I believe that's a documentation error. I encourage you to send feedback on the documentation - I have done so several times in the past and I have alwys got back a nice email telling me the document has been corrected and thanking me.

Step 7 in that guide references the "system install" command. That command installs the system software (as opposed to the boot image) onto the SSD.

They do that because the base unit disk storage space is not adequate for the Linux distribution with FirePOWER software plus room for event storage that's required for FTD (or AS  FirePOWER service module).

Thank you Marvin,


I managed to reimage the ASA to FTD after adding an SSD. Also I have sent feedback on the documentation as suggested.

Hi,

nine months has passed since you have posted this. 

Do we have support for AnyConnect on FTD now? If not, when can we expect to have it?

smailmilak  ,

AnyConnect VPN is not available on FTD. It will not be available in FTD 6.2 (the next release due out in a month or so).

We are told it is a high priority for the subsequent release - probably in mid-2017. However we won't know for sure until Cisco commits the release and puts out the release notes.

Hi Marvin,

We are going to buy Cisco 5508-FPWR-BUN . 

Our vendor gave us fTD image but we are asking for the firepower image as we do need anyconnect? 

We do not have anyconnect support in FTD.Am i right?

Is there any major difference in FTD image or if we can just use asa with firepower?

Please advise.

thanks!!

Regards

Vaibhav

AnyConnect support will be introduced in FTD 6.2.1 in the next month or so. Please see this thread where I mentioned it earlier today:

https://supportforums.cisco.com/discussion/13248066/cisco-asa-5516-x-licenses

There are major differences between ASA with FirePOWER services and FTD. The boot image, internal architecture, licensing and feature support are a few. 

I recommend having a look at one of the recent Cisco Live Melbourne presentations for more details. Go to ciscolive365.com and search under 2017 Melbourne for keyword FTD. 

BenBen
Level 1
Level 1

FTD definately is the right direction to take. It makes no sense to glue ASA and FirePower together and double performing access control functions.

Glad to see this happen, but comparing with other products, such as PA, this comes late.

Honver Lam
Level 1
Level 1

Has the ASA to FTD migration tool been released yet somewhere? I can't find it. Presentations and engineers have informed me that it would be released during the summer.

There is a migration tool but Cisco has decided not to make it public-facing at this time.

It is available for internal Cisco and partner use and was just made available this month (September 2016).

If you have a migration requirement, your Cisco or partner SE should be able to assist by using that tool.

I am a partner and I still can't find it. As the migration has no need for IPS at the moment, I guess I'll stick with the Firepower ASA image for now.

honvlyyyy  ,

Please see https://communities.cisco.com/docs/DOC-69629 (partner access required).

walter baziuk
Level 5
Level 5

does anyone know when the

ASA ASDM FirePOWER Threat Defense tool to migrate ->  FirePOWER Threat Defense will be released ?

i hate java and am having issue updating the FirePOWER Service module away from v6.0.0.1

Eduardo Marin
Level 1
Level 1

Hi all,

Somebody knew if/when the FTD image will support Routed Clustering? Same question for Firepower 9300/4100 regarding ASA Routed clustering.

I understand Cisco has Spanned Etherchannel Cluster functionality in FP 9300 with ASA image, but not Routed one. 

Regards

Review Cisco Networking products for a $25 gift card