03-22-2016 03:26 AM - edited 02-21-2020 10:21 PM
Hi
Can someone from Cisco please explain what this image is? And what parts of ASA does include ? Can it do VPN/Anyconnect ?
Is ASA OS getting retired ?
Regards
Solved! Go to Solution.
03-29-2016 06:46 AM
A migration tool will be offered later this year (ca. summer 2016).
Don't expect full feature parity until sometime in 2017.
03-29-2016 08:49 AM
Marvin thanks for answer it seems you know more than Cisco employees :D
04-06-2016 02:46 AM
@Marvin Rhoads
i can not find info about what feature it is going to support/not support?
http://www.cisco.com/c/en/us/td/docs/security/firepower/roadmap/firepower-roadmap.html
also i can not find the software to download it?
https://software.cisco.com/download/release.html?mdfid=286271171&flowid=77243&softwareid=286306337&release=6.0.1&relind=AVAILABLE&rellifecycle=&reltype=latest
Can you provide me with links please?
Regards
Walied
-------------------------------
edit:I just found, links added
03-29-2016 08:38 AM
Per: http://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5500X/ftd-55xx-X-qsg.html there are re-image options for many models, but I didn't see the 5585-x. These are a hefty investment. Will there be re-image or migration options for these?
03-29-2016 08:48 AM
On 5585-X FirePOWER runs on seperate blade. So afaik there wont be unified image.
03-29-2016 09:04 AM
Correct - there's not currently a unified image for the 5585-X hardware. As of right now that's not supported and it's TBD whether it ever will be.
Generally speaking the new FirePOWER 4100 and 9300 series is a much better fit for the high performance uses cases where the FTD image feature set is desired. That's from both a cost and performance perspective.
The 5585-X should be the platform of choice where the full ASA feature set (remote access VPN, clustering, multiple context etc.) is required, potentially with the (non-unified image) NGIPS features via the SSP blade.
I would expect Cisco will eventually offer Investment Protection Program (IPP) and Technology Migration Program (TMP) options for 5585-X customers if and when they are ready to migrate. (That's just speculation informed by past experience on my part and nothing that's been decided at this point as far as I know.)
03-28-2016 09:51 PM
I have a few questions.
Thanks.
03-28-2016 11:22 PM
Hi
>I am not 100% sure about whats the future roadmap for ASA as that is subject to change but FTD is the future.
>FTD unified image is combination of ASA and firepower so ASA OS is same but all the config is supposed to be done from GUI and not CLI. CLI can be used for troubleshooting and same set of commands used in ASA can be run in ASA part of it.
>There is no decision yet on when ASA OS will be discontinued as FTD doesn't yet support all of ASA features so we need to wait and see how things turn out but it will be quite some time.
>Yes FTD will be managed by Firepower management center.
>There will be a release (under roadmap) where ASDM can also manage both ASA and Firepower for few models but its under development. With current release , everything is being done from Firepower management center.
Thanks
03-29-2016 01:07 AM
>There will be a release (under roadmap) where ASDM can also manage both ASA and Firepower for few models but its under development. With current release , everything is being done from Firepower management center.
Why the heck would you want to manage FTD with old, ugly and JAVA based ASDM ?
This is currently possible with 9.3/9.4 ASA code w/ FirePOWER 6.x stuff.
>Yes FTD will be managed by Firepower management center.
No on-box management ? you need FMC VM/Appliance to manage FTD ?
07-19-2016 12:57 AM
Hi,
so the image works well, but we have problems with the SMART-Accound. could it be, that a downgrade to the ASASFR image is impossible?
I get the whole time Bad Magic Block errors....
kind regrads
07-19-2016 01:09 AM
Hello Team,
If you have any issues with the smart account , you need contact the below team.
For asa sfr other than downgrade, the reimage is possible. That is reinstalling the module once agian using the following link. Just try to search for keyword reimage in following link.
Its for the software module
http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html
Let me know if you have a hardware module.
rate if the post helps you.
Regards
Jetsy
10-05-2016 07:58 PM
Hi,
I want to ask for Reimage of Firepower Threat Defense on ASA5506-X.
Booting with image ftd-boot-9.6.2.0.cdisk ,I can download it from tftpdnld but doesn't appear boot system >. After download it, appeared as rommon #. Therefore I can't make install the image of ftd-6.1.0-330.pkg.
Thanks.
10-06-2016 04:15 AM
The .cdisk file is not for your hardware. As noted on the download page for that image, it is "Firepower Threat Defense v6.1.0 boot image for ASA 5512/5515/5525/5545/5555 devices".
The 5506, 5508 an 5516-X platforms require the cryptographically signed boot images. For the 5506, you would find file "ftd-boot-9.6.2.0.lfbff" here:
https://software.cisco.com/download/release.html?mdfid=286283326&flowid=77251&softwareid=286306337&release=6.0.1.2&relind=AVAILABLE&rellifecycle=&reltype=latest
Is is titled "Firepower Threat Defense boot image v6.1.0 for ASA 5506/5508/5516 devices".
Simply having an ASA does not entitle you to the advanced features of the FTD images. You need to license them using their own licensing structure, which is similar to the FirePOWER modules. There is a Base license (automatically included with new orders), in addition to Threat, Malware and URL Filtering licenses - the latter all term-based licenses that require Cisco Smart Licensing.
There is an FAQ posted here that explains the licensing in more detail:
https://supportforums.cisco.com/discussion/12944426/firepower-threat-defense-smart-licensing-faqs
10-06-2016 08:19 PM
Hi Marvin,
Thanks you for your kindly help. I can install the image ftd-6.1.0-330.pkg.
Thanks.
10-07-2016 07:31 PM
You're welcome. Please rate the reply if it helped.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide