06-24-2024 09:25 AM
Is it possible in multi-instance mode to run both the FTD and the ASA images? Currently in the process of replacing both the 7125 IPS and the 5555-X firewalls with the 3120.
06-24-2024 09:30 AM
Firepower 9000 support mix asa and ftd
But for 3000 series I suggest ask cisco about if this feature available or not.
MHM
06-24-2024 11:04 AM
No - mixed mode logical devices is NOT supported on the 3100 series not are their plans to do so.
As @MHM Cisco World noted, only the 9300 series supports that capability (by using separate hardware security modules).
06-26-2024 06:13 AM
Thanks guys. The documentation needs to be a bit more clear on the subject. 3100 series supports multi-instance, and states that each instance runs it's own image of software, but does not clarify whether it can be FTD & ASA on the same platform, but now that I have a 3120 on my desk, I can clearly see both images in firmware, and after trying to upgrade with failures due to a bug in the recommended ROMMON, when switching to ASA image, it wipes FTD and FXOS off the platform. Then to get FTD it has to be re-imaged. Either way though it does accomplish my end goal of an IPS in front of our routers and firewall, I just need to learn how to create a firewall that matches the current 5555-X on FTD.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide