cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1128
Views
5
Helpful
4
Replies

ASA with FirePOWER

fabflorent
Level 1
Level 1

I want to order ASA 5515 with FirePOWER.

Did the new order include free 1 year licence for any FirePOWER feature, or should I purchase automatically licence ?

What is the minimum subscription recommanded ?

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

The only thing you get for free is the Control license. It gives you application visibility but no IPS, URL Filtering or Malware protection.

You should have the IPS subscription at the very least.

I'd give 2nd priority to Malware only because I would first recommend an endpoint protection scheme like AMP for Endpoints. An endpoint product like that gets you ahead of the whole SSL arms race as the files are unencrypted on the endpoint.

Similarly with the URL Filtering I would personally recommend a solution like Cisco Umbrella (former OpenDNS) as more effective.

If you don't have any endpoint or DNS protection then I recommend the full IPS, URL Filtering and Malware licensing.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

The only thing you get for free is the Control license. It gives you application visibility but no IPS, URL Filtering or Malware protection.

You should have the IPS subscription at the very least.

I'd give 2nd priority to Malware only because I would first recommend an endpoint protection scheme like AMP for Endpoints. An endpoint product like that gets you ahead of the whole SSL arms race as the files are unencrypted on the endpoint.

Similarly with the URL Filtering I would personally recommend a solution like Cisco Umbrella (former OpenDNS) as more effective.

If you don't have any endpoint or DNS protection then I recommend the full IPS, URL Filtering and Malware licensing.

Thanks Marvin

You're welcome. Thanks for rating.

One small addition to Marvins perfect answer: Today, I would consider buying the ASA 5516-X instead of the ASA 5515-X. That device has more physical interfaces, is more modern and powerfull but only slightly more expensive.

Review Cisco Networking for a $25 gift card