06-22-2019 03:20 PM - edited 02-21-2020 09:14 AM
Hello Expert,
We have an ASA 5525 that was running since 1 year now.
we have purchased firewpower service licenses.
We are juste interested in ips part of that service.
My question is : can asa image still handle the access-list and forward the allowed packets to firepower services ?
Regards,
Karim
06-23-2019 10:32 AM
yes your ASA works as usal like FW, if you like to use IPS Service you need add additional configuration to intercept the traffic
look at the configuration guides :
06-24-2019 07:23 AM
When using a Firepower service module, the ASA continues to do everything it always has (ACL, NAT, VPN etc.) with the addition of having the Firepower services module to do IPS (and URL Filtering and Advanced Malware Protection if you desire and have the licenses).
See the order of Operations for ASA packet processing diagram below for a visual illustration:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide