08-27-2015 10:35 AM
Hello Friends
In the past, I worked many times with the ASA with CX module. If you wanted to setup a failover pair with two CX modules, you only need one suscription (for expamle WSE, IPS, AVC), and then PRSM used to assign the licenses to the current Active device.
Now with the firepower module, I have read the user guide for many times and I´m not able to figure out if we wanted to implement an Active / Stanby pair, do we need one license for each firewall? Or just we need One license for the two firewalls?
Plase, feel free to request as much information as needed. Any comment or documentation will be appreciated.
Best Regards!
Solved! Go to Solution.
08-28-2015 05:45 PM
Each and every FirePOWER module needs a unique license assigned to it from the managing FireSIGHT Management Center (aka Defense Center).
The same applies whether they are part of ASAs in a HA pair, a cluster, or wholly separate.
08-28-2015 05:45 PM
Each and every FirePOWER module needs a unique license assigned to it from the managing FireSIGHT Management Center (aka Defense Center).
The same applies whether they are part of ASAs in a HA pair, a cluster, or wholly separate.
03-25-2017 06:22 AM
Hi Marvin,
We are going to buy asa 5508-X which would be in cluster and having TAMC license with URL, AMP services.
Do i need to buy two licenses for the cluster?
Regards
Vaibhav
03-25-2017 06:36 AM
Yes.
The advice I had provided 2 years ago remains valid. Each FirePOWER service module must be separately licensed.
Several of us partners have raised the issue with Cisco sales, asserting that this is a bit unfair in the case of an Active-Standby HA pair. To date the situation remains unchanged.
03-25-2017 06:41 AM
Thanks Marvin. It helps.
I know this is not related to this discussion but can ASA (5508-x) be integrated with a DLP solution ( say McAfee ) . . I have read it works with cisco WSA but not with ASA.
03-27-2017 11:29 AM
It could, with Firepower, under some conditions. If you are referring though files, it can block files that you provide the SHA sum for them, though unencrypted channels or encrypted with decryption policies channels.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide