cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
1508
Views
0
Helpful
2
Replies
Beginner

Change firepower IPS module from monitor mode to block mode

I want to upgrade 2 cisco asa 5515x to include firepower IPS modules and

  • configure new IPS sensors in monitor mode and add to FMC with new policies
  • post the analysis for any false positives, change the sensors to block mode.

Please guide me how I can achieve this.

Thanks in advance.

 

Everyone's tags (2)
1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Master

Re: Change firepower IPS module from monitor mode to block mode

The Firepower module gets traffic from the parent ASA by applying a service-policy to an interface (or globally). The service-policy references a policy-map which in turn references a class-map. 

 

In the class-map the key command is:

 

sfr { fail-close | fail-open } [ monitor-only ]

You would use that optional "monitor-only" keyword to operate in IDS mode. When you are ready to move to IPS mode simply change that one line.

 

Here are some helpful references:

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s1.html#pgfId-1660444

 

https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html#anc10

2 REPLIES 2
Hall of Fame Master

Re: Change firepower IPS module from monitor mode to block mode

The Firepower module gets traffic from the parent ASA by applying a service-policy to an interface (or globally). The service-policy references a policy-map which in turn references a class-map. 

 

In the class-map the key command is:

 

sfr { fail-close | fail-open } [ monitor-only ]

You would use that optional "monitor-only" keyword to operate in IDS mode. When you are ready to move to IPS mode simply change that one line.

 

Here are some helpful references:

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/S/cmdref3/s1.html#pgfId-1660444

 

https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html#anc10

Highlighted
Beginner

Re: Change firepower IPS module from monitor mode to block mode

Thanks for your response, Marvin.

CreatePlease to create content
Content for Community-Ad
August's Community Spotlight Awards