Cisco Firepower 4110 NGFW Multi Context mode.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-07-2018 04:21 AM - edited 02-21-2020 07:29 AM
Hi,
We want to deploy Cisco Firepower 4110 NGFW Appliance as a Multi context mode with 6 number of virtual context. Now my query is that, can we deploy 3 number context at router mode & other 3 number context in transparent mode ?
also if possible please share a cisco documents.
Regards,
Suman Samanta
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-07-2018 07:14 AM
I assume you are planning an ASA logical device on the 4110 since FTD logical devices do not currently support multiple context mode.
You can set the firewall mode independently for each context in multiple context mode.
That is regardless of whether it's a physical ASA or an ASA logical device on a Firepower hardware appliance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2018 06:43 AM
Hi Marvin,
Thanks for your reply,
But I want to clarify that we have 2 no hardware Cisco Firepower 4110 NGFW appliance, we want HA between these two appliance. After that we want to convert the appliances to context mode. Is it possible to do this ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2018 07:14 AM
The high availability is established between the ASA logical devices running on the Firepower hardware chassis'. The hardware itself (which runs FX-OS) and the Firepower Chassis Manager used to manage it is unaware of any HA.
You would have to install an ASA logical device on each and then setup multiple context with HA between the ASAs. You do it the same way as if it was running on ASA hardware.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2018 05:20 PM
Hi thanks for your reply,
I need another clarification that if we create 6 umber multi context mode in my HW ASA & between these can we create 3 number context in transperent mode or bridge mode & rest of 3 context in router mode of NAT mode. Is it possible ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2018 06:37 PM
If you have the licenses for multiple contexts you can do that.
The modes are known as "transparent" and "routed". There is no "bridge" or "nat" mode although you can essentially perform those functions.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-11-2018 11:25 PM
HI Marvin,
Thanks for your Reply.
Now I understand..
One think, can you share any "Transparent” mode related deployment guide. It will be helpful for me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2018 10:26 AM
The configuration guide is a good place to start with learning how to setup transparent mode.
Other than that, check out some of the good books like:
http://www.ciscopress.com/store/cisco-asa-all-in-one-next-generation-firewall-ips-and-9781587143076
...or take an ASA course.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-26-2018 12:58 AM - edited 12-26-2018 12:58 AM
Dear Marvin,
Cisco FPR4110 supports multiple context - 10 included, 250 max when running ASA image, is there roadmap for FTD image context support?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-26-2018 02:47 AM
FTD 6.3 introduced multiple instance support for Firepower 4100 and 9300 series appliances. Here's a link to the section of the configuration guide showing the capabilities:
There are no plans for this to be supported on ASA appliances running FTD.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-26-2018 10:57 AM
Thanks Marvin, great! I was just looking on the data sheet and could not find this info. Just in time for another proposal. Cheers!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-26-2018 06:44 PM
You're welcome. Please mark the reply as helpful it is was.
