cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4518
Views
10
Helpful
5
Replies

Cisco ASA with FirePOWER vs. FTD

alsayegh
Level 1
Level 1

Hello,

 

I have ASA 5555-X with FirePOWER which I didn't use yet. I downloaded two images for it, then asasfr-sys and ftd. I assume that the appliance comes with the asasfr preinstalled and one must reimage it with ftd if FirePOWER services is needed. Is this assumption correct?

 

If the device is labeled as "ASA with FirePOWER", shouldn't FirePOWER services come standard with it? Or does it come with limited FirePOWER features in the original asasfr image and must reimage with ftd to unlock all the FirePOWER features?

 

In general, what is the main difference between the two image and which one when would use either one?

 

Will the ASA image phase out and Cisco focus on the FTD image for these appliances in the future?

1 Accepted Solution

Accepted Solutions

To download the FTD firmware you need a service contract in place between cisco and you company. In regards to SMARTnet license I have pasted below information from cisco website. here all the information is how to setup a smart lic. cisco firepower license come with 1/3/5 years subscription. 

800.PNG

 

801.PNG

please do not forget to rate.

View solution in original post

5 Replies 5

Sheraz.Salim
VIP Alumni
VIP Alumni

have ASA 5555-X with FirePOWER which I didn't use yet. I downloaded two images for it, then asasfr-sys and ftd. I assume that the appliance comes with the asasfr preinstalled and one must reimage it with ftd if FirePOWER services is needed. Is this assumption correct?

 

ASA 555-X series come out of box with ASA code (9.x) and sfr module (firepower sensor) with it. You can covert the 5555-X onto FTD.however just to let you know the ASA sfr need traditional lic where as FTD need a smart lic. your understanding is correct.

 

 

If the device is labeled as "ASA with FirePOWER", shouldn't FirePOWER services come standard with it? Or does it come with limited FirePOWER features in the original asasfr image and must reimage with ftd to unlock all the FirePOWER features?

 

SFR and ASA code work together in order to give you a L7 inspection (deep packet inspection). FTD is a unified software (mean its a combination of ASA code and Snort) you can get the same thing with either running the FTD or ASA with SFR. having said that, if you have a large deployment where the firewall is heavily used and you are more focused on security. than FTD is more better way to use (that my opinion).

 

 

In general, what is the main difference between the two image and which one when would use either one?

as said they both are same. FTD is more unified compare to ASA sfr. as FTD is combination of Snort and ASA that could explain to use the FTD have more preference than ASA.

 

 

Will the ASA image phase out and Cisco focus on the FTD image for these appliances in the future?

no i dont think so. ASA code at layer 4 is one of the best firewall we have ever seen it will stay long for sure. old school engineer like me love ASA code and i am sure cisco knew that. cause of this cisco also support ASA code on new FTD appliances like 2100/4100/9000 series.

 

 

please do not forget to rate.

Thank you, Sheraz, for the elaborate response. You explained it well. The only remaining question relates to the point your raised regarding the required licensing. I bout SMARTnet license. That's how I downloaded the FTD firmware. Is that what you mean? but the SMARTnet license is valid for only limited time. What will happen after the perid ends? I won't be able to download updates only or the FTD will completely stop working or only some features will stop working?

To download the FTD firmware you need a service contract in place between cisco and you company. In regards to SMARTnet license I have pasted below information from cisco website. here all the information is how to setup a smart lic. cisco firepower license come with 1/3/5 years subscription. 

800.PNG

 

801.PNG

please do not forget to rate.

Thank you for your explanation. I can see that half of the components in FTD are perpetual, and perhaps the perpetual part of FTD is almost equivalent to ASA, so even if the term-based part expires, the FTD is still an attractive option.

@alsayegh it depends on you. how much comfortable you feel running with FTD. if you plan to go ahead with FTD. you going to manage this from FMC or stand alone FTD? does your team have a skill set to configure the FTD compare to ASA.

 

please do not forget to rate.
Review Cisco Networking for a $25 gift card