cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1827
Views
5
Helpful
4
Replies

ASA appliance vs ASA as a logical device on Firepower

ashishb.sharma
Level 1
Level 1

As per the link

https://www.cisco.com/c/en/us/products/collateral/security/asa-firepower-services/eos-eol-notice-c51-743545.html#Productmigrationoptions

 

The migration solution for the ASA5525, ASA5545 & ASA5555 is the Cisco Firepower 2100 Series Appliances. I tried to find if there is a comparison matrix between the ASA as appliace vs ASA as logical device on Firepower. Cant seem to find any not even things which are supported/not supported on each. 

 

Got this link for ASA deployment but it is for 4100 series

https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp4100/firepower-4100-gsg/asa_deploy.html

 

Nothing much available in terms of the comparison/differences which needs be looked at in terms of the ASA being deployed as a logical device. For example management/monitoring/interfaces/ASDM/FDM etc.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

ASA hardware appliances are being mostly end of sales as of 2020.

Running ASA on Firepower hardware vs. ASA on ASA hardware (5500-X series) has mostly equivalent ASA features but Firepower appliances will have much higher throughput.

One thing you WON'T get is the ability to add a Firepower service module when running ASA on Firepower hardware. To get Firepower features on Firepower appliances you will need to run the FTD image.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

ASA hardware appliances are being mostly end of sales as of 2020.

Running ASA on Firepower hardware vs. ASA on ASA hardware (5500-X series) has mostly equivalent ASA features but Firepower appliances will have much higher throughput.

One thing you WON'T get is the ability to add a Firepower service module when running ASA on Firepower hardware. To get Firepower features on Firepower appliances you will need to run the FTD image.

@Marvin Rhoads thanks for your reply but this is what is confusing for me. From the link

https://www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html?referring_site=RE&pos=2&page=https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html#id_59069

 

Table 6 shows the ASA or FTD, and Firepower 4100/9300 Compatibility and pretext to table 7 states for Firepower 1000 and 2100 you cannot install ASA or FXOS separately; you must install them both as part of the bundle.

 

From the link https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-vs-ftd/td-p/2958639 there is a comparison chart showing feature comparison but this one is for  differences between ASA with Firepower Services and FTD.

 

I checked a  lot of datasheets and documents but cant seem to find any definitive approach that Cisco provides for customers who want to migrate to a Firepower series device and run ASA as a logical device on the same.

 

Wondering if there will be anything around this soon or I have to do it the hard way by picking bits and pieces from different documents.

 

 

FTD is a unified software which consists of 2 main engines, the Snort engine and the LINA engine.FX-OS and FTD have independent control planes. "You cannot install ASA or FXOS separately; you must install them both as part of the bundle." just think FXOS as a bootstrap image. one this up and running than you can either run FTD image or ASA image. in other word the per-requiste for new firepower appliance they must have to run the FXOS.

at the moment of time only multi-instance is supported on Firepower 4100/9300. if you want to mix macth for example you want to run ASA and FTD this is planned for future release and will supported in 9300 @Marvin Rhoads correct me if I am wrong.

 

 

 

please do not forget to rate.
Review Cisco Networking products for a $25 gift card