cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2273
Views
0
Helpful
3
Replies

Firepower without subscription

S891
Level 2
Level 2

hi, 

I want to ask what features are available in FTD if I purchase it without any subscription (AMP, IPS, URL filtering etc.). FTD configuration options seems overwhelming and it is difficult to figure out for a newbie to know what can and what can't be done with only the base firewall. 

 

Thanks 

3 Replies 3

Francesco Molino
VIP Alumni
VIP Alumni
Hi

Without any subscriptions you'll be able to configure rules like you do on asa but with a different gui.

FTD is the next gen firewall unified image and without subscriptions you can't do too much. And if you don't have any FMC, then don't go to FTD, take s new generation box and image it with asa.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

mikael.lahtela
Level 4
Level 4

Hi,

 

As mentioned, L4.

Base Licenses The Base license allows you to:

• implement user and application control by adding user and application conditions to access control rules

• configure your Firepower Threat Defense devices to perform switching and routing (including DHCP relay and NAT)

• configure Firepower Threat Defense devices as a high availability pair

• configure security modules as a cluster within a Firepower 9300 chassis (intra-chassis clustering)

• configure Firepower 9300 or Firepower 4100 series devices running Firepower Threat Defense as a cluster (inter-chassis clustering) Your purchase of a Firepower Threat Defense device or Firepower Threat Defense Virtual automatically includes a Base license.

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Licensing_the_Firepower_System.pdf

 

br, Micke

Thank you for your responses. What is the extent of application and user control? Can I do, for example, social media restriction, bit-torrent restriction etc? 

 

I think for user restriction I will have to do AD integration. How would I get the updated information on application f I don't have a subscription?  

Review Cisco Networking products for a $25 gift card