cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
985
Views
0
Helpful
1
Replies

Deploy SFR: Inline or Monitor

fcorre
Level 1
Level 1

Dear

How are you? Implementing two sfr modules in ASA failover firewall will be managed by an FMC. For 3 weeks you will be only monitoring the traffic and analyzed through the FMC to define the signature bases that we will block, I have a period to leave it in "Inline Tap Monitor Only", What do you recommend? or leave it online (sfr fail-open) without a monitor and in the FMC allow all traffic?

 

Firepower policy map
class firepower class
sfr fail-open monitor-only

 

Thanks very much.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

I'd say it's easier to do the monitor-only in the ASA policy-map configuration.

 

That way it's a one-line immediate effect change to revert it.

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I'd say it's easier to do the monitor-only in the ASA policy-map configuration.

 

That way it's a one-line immediate effect change to revert it.

Review Cisco Networking products for a $25 gift card