cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
984
Views
0
Helpful
1
Replies

Deploy SFR: Inline or Monitor

fcorre
Level 1
Level 1

Dear

How are you? Implementing two sfr modules in ASA failover firewall will be managed by an FMC. For 3 weeks you will be only monitoring the traffic and analyzed through the FMC to define the signature bases that we will block, I have a period to leave it in "Inline Tap Monitor Only", What do you recommend? or leave it online (sfr fail-open) without a monitor and in the FMC allow all traffic?

 

Firepower policy map
class firepower class
sfr fail-open monitor-only

 

Thanks very much.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

I'd say it's easier to do the monitor-only in the ASA policy-map configuration.

 

That way it's a one-line immediate effect change to revert it.

View solution in original post

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I'd say it's easier to do the monitor-only in the ASA policy-map configuration.

 

That way it's a one-line immediate effect change to revert it.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card