cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3959
Views
0
Helpful
12
Replies

CISCO ISR 4000 Series with FTD

dpsw120
Level 1
Level 1

Hello All.

 

I have Cisco 4321 as NAT and GW device for my server. I need and IDS/IPS for security and i need some suggestion for this, can anyone help me please. I'm thinking about buying ASA5516-FTD-K9 or buying UCS E-Series Server Blade and run UTD on that.

 

Please help thank you.

12 Replies 12

balaji.bandi
Hall of Fame
Hall of Fame

ISR support FTD Modules, you can use Firepower features

 

the below good FAQ for reference :

 

https://blog.router-switch.com/2017/08/faq-cisco-firepower-threat-defense-for-isrs/

 

Otherside if you have the budget, i will buy a separate device (FTD 1XXX or 2XXX depends on network), so there is no dependencies, again depends on user requirement.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I think i read about that using ucs module, will it support ips and stateful firewall?

How about using asa5516 with ftd? Because 1000 series and 2000 series not ready in my distributor and i already have internet connect to 4321 where should i put that device?

Thank you

will it support ips and stateful firewall?

 

The URL i have provided has all the information what is support on ISR

 

Q: What are the elements of Cisco Firepower Threat Defense for ISR?

A: There are five components:

  • Firepower Next-Generation Intrusion Prevention System (NGIPS) sets the standard in advanced threat protection, integrating real-time contextual awareness, intelligent security automation, and industry-leading threat prevention effectiveness.
  • Application Visibility and Control (AVC) reduces the potential surface area of attacks through detailed control of thousands of applications and by enforcing mobile app, social media app, and acceptable-use policies.
  • Advanced Malware Protection (AMP) for Networks protects against highly sophisticated, targeted, zero-day attacks, and advanced persistent malware threats. It continuously analyzes files and network traffic for threats that evade first lines of defense, provides deep visibility into the activity and behavior of a threat, and then lets you quickly scope the impact of an active attack and contain it with a few clicks.
  • Reputation-based URL Filtering mitigates sophisticated client-side attacks – and improves employee productivity – by controlling access to more than 280 million URLs in more than 80 categories and reducing the risk from suspicious or unacceptable domains.
  • Cisco FirepowerManagement Center is the centralized point for event and policy management for all of the Firepower Threat Defense for ISR components.

How about using asa5516 with ftd?

 

5516-X  support FTD.

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5508X/ftd-fmc-5508x-qsg.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

The URL i have provided has all the information what is support on ISR

It is support IPS and Stateful Firewall, i'm sorry sir. But i need to check if UCS ready or not in my distributor.

5516-X support FTD

Can i implement FTD before Router? I mean in the edge and router still have wan ip because that way i wouldn't have to change configuration on running Router. And it already had nat forwarding to internet and dmpvn configured to office, it will be a mess if i should reconfigure my running Router.

Can i implement FTD before Router?

 

Yes possible, but this time you need to deploy as transparent mode, some of the advanced features may not get effective while you doing in Transparent Mode.

 

If you like to deploy in Routed Mode, you need to make necessary design changes to get optimal results.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yes possible, but this time you need to deploy as transparent mode, some of the advanced features may not get effective while you doing in Transparent Mode.

 

- what advanced features that won't effective if im doing in Transparent Mode

 

If you like to deploy in Routed Mode, you need to make necessary design changes to get optimal results.

 

- that would be a mess because this is my current implementation

Test.JPG

I forgot to add my router run dmvpn for drc and office

Any transparent firewall is a Layer 2 firewall that acts like a “bump in the wire,” or a “stealth firewall,” and is not seen as a router hop to connected devices.

 

in use cases where you want to forward all the L2 traffic via FW. ( you have difficulties to change topology in exiting environment and deploy FTD inline.)

un supported features :

 

1. DHCP relay

2. routing protocol (only static allowed)

3. multicast routing.

4. QoS

5. VPN.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

So transparent would be the best in my case right? Because my router still get public ip and i didn't need to change any configuration on my router.

And for un supported features :
1. DHCP relay
2. routing protocol (only static allowed)
3. multicast routing.
4. QoS
5. VPN.
-point 1 i don't need dhcp relay nor server.
-point 2 to 5 all of this will be handle by my router

yes, in that case, the right candidate for you.

 

you can also contact Local SE to deploy one for you before you buy one..so you are confident enough for asking funds to management or business

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

yes, in that case, the right candidate for you.

- that's great, thanks for the discussion but 1 more question, if i want to use UCS E-Series Servers in my isr 4000 as ftd is there any downside using this than separate device asa 5516-x-ftd?

you can also contact Local SE to deploy one for you before you buy one..so you are confident enough for asking funds to management or business

- what is local se? so it's like testing before buying?

Personally I do not see any downsize, but its dependency (if no other option like a branch, you can do all in one - because single box maintenance.)

 

If i were you if the budget available i got with a different box.

 

yes local cisco partner test and buy model, so you know what you buying and tested as per your environment.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

We have 2 site and each site had 2 isp and 2 router i think those 2 site need 2 each because isp am i wrong?

I'll try to ask to our cisco local partner about this.

Review Cisco Networking for a $25 gift card