cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
913
Views
5
Helpful
1
Replies

ASA Threat Detection vs Firepower

rob@pri-med.com
Level 1
Level 1

Is it overkill to have threat detection scanning on an ASA 5516 with Firepower services? Can I get the same and better protection from Firepower only?

The reason for my question is that I get several tickets a day to un-shun VPN users. It's not always the same users, but there are a handful that are frequent callers. I can never catch when they get shunned and there seems to be no common trait. And rather than white-list the VPN IP Pool, I'd like to know if I lose some security if I disable threat detection on the ASA?

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

I've never found the ASA threat detection feature particularly useful. I almost never see it enabled on customer ASAs (and I have seen hundreds of those).

A properly configured Firepower service module definitely provides superior threat protection vs. what's offered in the base ASA.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card