01-05-2017 01:04 AM - edited 03-12-2019 01:44 AM
Hello,
Whats the difference between traditional Cisco ASA with firepower vs new Cisco Firepower threat defence.
why customer will go for Firepower threat defence, if they already have Cisco ASA with firepower services.
what are the benefits of FTD and additional features in FTD?
I also would like to know, what are the key benefits of Cisco Firepower appliances (4100, 9300) and what are the limitation of Firepower Appliances?
what are the difference between FTD and Firepower appliance?
in which scenarios they use and other use cases?
Thanks
01-05-2017 03:21 AM
FTD combines both asa and firepower code into a single image. At the moment FTD has not reached feature parity with ASA features (no remote-access vpn, no multiple-context mode, no clustering, etc.) but it will be the way forward.
One of the benefits is that you wont need to configure two seperate instances (ASA & Firepower), but have a unified security policy that is managed either with Firepower Device Manager for small to mid-range deployments (ASA 5506-X - 5525-X) or using the central management with Firepower Management Center.
The Firepower appliances (4100, 9300) are the new NGFW hardware platform that can run either ASA (without firepower services) or FTD software. They are basically the evolution of the asa hardware platform that support higher throughput.
You may want to go down the FTD road if do not require the features not yet implemented from ASA as stated above. In about two years it should be the defacto standard.
Feature Comparison (Q4, 2016):
02-15-2018 02:24 AM
Hi,
could you tell me from which document that picture is from? I am searching for a recent document, but was unable to finds something.
Kind Regards
Sebastian
02-15-2018 05:54 AM
02-15-2018 08:51 AM
Thanks, that was the answer I was looking for!
01-29-2021 02:22 AM - edited 01-29-2021 02:23 AM
Hi Oliver, very useful is their a newer version of this comparison chart for 2020/21? thanks
01-05-2017 04:18 AM
You've asked some very broad questions. Here are a few answers.
FTD is an integrated image which combines all of the FirePOWER Services features with many (but not all) ASA firewall services.
If a customer is already running ASA with FirePOWER services, they may want to migrate in the long term to simplify management and operations. Short term, there are few compelling reasons.
Right now there are very few FTD features that are not available with a combination of ASA and FirePOWER services. Longer term, more developement resources on the FTD side may change that equation.
The 4100 and 9300 series are a whole new hardware platform for security appliances based on the UCS hardware. They offer much higher performance for a very attractive price when compared to the ASA platforms.
FTD runs on either the new 4100 and 9300 series or the ASA appliances (except 5585-X). FirePOWER appliances run only the legacy FirePOWER image and will not run FTD image.
06-03-2018 05:03 AM
Hi Marvin,
"" Firepower appliances run only the legacy FirePOWER image and will not run FTD image"
Can you please explain which are the firepower appliances that you are referring to here ?
@Marvin Rhoads wrote:
You've asked some very broad questions. Here are a few answers.
FTD is an integrated image which combines all of the FirePOWER Services features with many (but not all) ASA firewall services.
If a customer is already running ASA with FirePOWER services, they may want to migrate in the long term to simplify management and operations. Short term, there are few compelling reasons.
Right now there are very few FTD features that are not available with a combination of ASA and FirePOWER services. Longer term, more developement resources on the FTD side may change that equation.
The 4100 and 9300 series are a whole new hardware platform for security appliances based on the UCS hardware. They offer much higher performance for a very attractive price when compared to the ASA platforms.
FTD runs on either the new 4100 and 9300 series or the ASA appliances (except 5585-X). FirePOWER appliances run only the legacy FirePOWER image and will not run FTD image.
to here ?
05-12-2020 08:30 AM
CIsco Firepower is garbage
Keep the ASA at least you can do stuff with it
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide