07-20-2021 05:27 AM
Hi All
I was wondering if someone enables and uses the FirePOWER module Cisco ASA without FMC.
I didn't find documentation clearly about it.
Any help is welcome.
Cheers
Alex
07-20-2021 09:18 AM
You question isn't that clear but you can manage Firepower services using ASDM
Hope this helps
Chakshu
Do rate helpful posts!
07-20-2021 11:14 AM
Thank you
But if we have inside and outside interface for example:
Can we enable just for check traffic in interfaces?
Thank you a lot.
Cheers
Alex
07-20-2021 12:33 PM
I understood but I was wondering if we can enable IPS (by pass) in each Security zone Interfaces like this below
Thank you
Alex
07-20-2021 11:34 AM
The Firepower service module ("sfr") is referenced in the global_policy policy-map. As such, the ASA sends traffic to the sfr module based on a matched class-map ACL.
So whatever traffic matches the ACL (often "ip any any") is sent to Firepower for inspection. Not just traffic on one interface or another.
07-20-2021 12:20 PM
07-20-2021 07:58 PM
If you migrated to FTD you could do a prefilter rule to trust those zones and thus bypass Snort (Firepower) altogether.
In an ASA with Firepower service module I believe you would have to craft the ACL used to select the traffic inspected by Firepower to not include the subnets in the zones where you don't want inspection.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide