08-19-2024 05:29 AM
Hello Everyone,
I am migrating from a ASA with SFR module to aFTD running ASA image and another FTD running inline sets. The plan is to replace ASA with FTD running ASA image and SFR with an FTD running inline sets. In the current ASA we have around 31 sub interfaces and our target is to connect the FTD (running ASA image) and FTD (IPS) to a switch , then direct the traffic to IPS using VLAN pairs. Since there are sub interfaces in the ASA we would need the same in FTD inline sets to properly direct the traffic to the IPS so that the device connectivity can be done through a switch. Does the FTD support sub interfaces to configured as inline pairs or does it have something like VLAN pairs like old Cisco IPS?. What would be the approach I should follow in such a scenario?.
Kindly advise
Shabeeb
08-19-2024 01:58 PM
Inline sets and passive interfaces support physical interfaces and EtherChannels only, and cannot use VLANs or other virtual interfaces, including multi-instance chassis-defined subinterfaces.
**Please rate as helpful if this was useful**
08-19-2024 02:31 PM
Hello,
Thanks a lot for your response. So we need to put the IPS physically between the switch and the ASA right?.
08-19-2024 02:43 PM - edited 08-19-2024 03:12 PM
I am not so sure you need to try
SW(trunk)-link-FTD1 IPS-only-link-FTD2 with subinterface
FTD IPS-only not remove the header which include the VLAN
if it remove header then config
SW(access port)-link-FTD1 IPS-only-link-FTD2
here the IPS even if it remove the l2 header the traffic not drop
MHM
08-19-2024 03:08 PM
Correct.. put the FTD in the middle and it should work just fine.
**Please rate as helpful if this was useful**
08-20-2024 07:19 AM
Hello,
Thanks a lot for your reply. We have 3 segments, and I am planning to put the FTD inline pair in all the three segments. Please find the attached diagram.
I have the below concerns
Thanks
Shabeeb
08-27-2024 01:10 AM
Hi friend
Can we review your issue here,
Why you use ftd ips-only and ftd in series why you not use ftd and run IPS with it?
Did yoh have a load traffic?
MHM
08-27-2024 01:16 AM
Hello,
Thanks a lot for your reply. The customer currently has ASA with SFR modules. They have around 30 VPN tunnels in the firewall, and they are a bank. They would like to make sure the migration is very smooth. When we checked with local cisco team for design suggestion, they informed that FTD with ASA image + Separate FTD with IPS is the recommended design for banking customers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide