
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 06:49 AM - edited 02-21-2020 09:31 AM
Dears,
I am planning to implement Fortinet Sand boxing solution and i have a ASA with firepower services, will this solution will work ??? the file which will be send to fortinet sandboxing by ASA will be recognized???
Please confirm.
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:45 PM
When you use Firepower with an AMP (File) license, it communicates with the AMP public cloud via https (TLS over tcp/443).
It does not provide any feature or function to integrate with a third party on-premise sandboxing solution.
It can work with an AMP private cloud appliance in conjunction with a Threatgrid on-premise solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 08:05 AM
A Cisco ASA (with or without Firepower services) has no capability that I am aware of to send files for analysis to third party products.
That is only available with Cisco's AMP license which uses the Cisco's Threatgrid cloud-based sandboxing services for analysis of unknown files.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 10:03 AM - edited 09-25-2019 10:11 AM
Dear Marvin
Amazing, you have replies almost for all question i appreciate you dear.
so u are confirming me that it will not work with fortinet sandboxing solutions, but i want to know by what protocol FTD/ASA communicates with sandboxing either on cloud or on premises, if i m not wrong on cloud it will communicate with http/https or 8443, but what about on premises sand boxing solution.
That is only available with Cisco's AMP license which uses the Cisco's Threatgrid cloud-based sandboxing services for analysis of unknown files.
for the above sentence according to your reply , apart from the Threatgrid cloud-based sandboxing it can also work with on premises sandboxing solution. please correct me if i m not wrong.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2019 07:45 PM
When you use Firepower with an AMP (File) license, it communicates with the AMP public cloud via https (TLS over tcp/443).
It does not provide any feature or function to integrate with a third party on-premise sandboxing solution.
It can work with an AMP private cloud appliance in conjunction with a Threatgrid on-premise solution.
