cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2811
Views
0
Helpful
5
Replies

ASA FirePower Passive Monitor-Only

cofee
Level 5
Level 5

Hello,

 

Is there any possibility to configure a traffic-forwarding interface and connect it to a SPAN port on a switch when ASA with FirePower module is configured in routed mode? Is there any workaround?

 

 

Thanks!

2 Accepted Solutions

Accepted Solutions

mikael.lahtela
Level 4
Level 4
Hi,

If you are going to follow the guides you need to have the ASA in transparent mode to listen to a SPAN port.
The connection needs to be established in routed mode before it is sent to the ASA Firepower module.
Don't think there is a workaround for this.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.pdf

br, Micke

View solution in original post

Julio Carvajal
VIP Alumni
VIP Alumni

Hi,

 

Unfortunately No.

 

You have to run it in Transparent mode in order to make this happen.

 

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

5 Replies 5

mikael.lahtela
Level 4
Level 4
Hi,

If you are going to follow the guides you need to have the ASA in transparent mode to listen to a SPAN port.
The connection needs to be established in routed mode before it is sent to the ASA Firepower module.
Don't think there is a workaround for this.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.pdf

br, Micke

Julio Carvajal
VIP Alumni
VIP Alumni

Hi,

 

Unfortunately No.

 

You have to run it in Transparent mode in order to make this happen.

 

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks for the response. I have a spare asa 5510 with an IPS module (ssm 10), is it possible to configure this firewall for SPAN and analyze traffic using IPS/IDS module?

Hey Coffee,

 

no, the only way to redirect the traffic is from the ASA itself (on this model).

 

 

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks everyone!
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card