10-06-2018 01:29 AM - edited 03-12-2019 07:01 AM
Is there way to configure the Firepower 2100 as NGIPS in HA. We need to deploy FPR 2140 without making any routing changes in adjacent devices.
I can see the options only for Routed/Transparent Mode .
Solved! Go to Solution.
10-09-2018 09:17 AM
Correct the data plane interfaces don't have IP addresses in your use case.
The failover interfaces can be thought of as control plane. They will send heartbeats and other status along with configuration synchronization between the two appliances.
10-06-2018 02:18 AM
Have a look at this link for HA configuration for NGIPS firewalls.
10-06-2018 02:26 AM
10-06-2018 03:18 AM
The document is for FTD 9000 series but the configuration remains the same for 2140 also.
Here is a link for HA for FTD4100 but as mentioned configuration is the same for 2140.
https://finkotek.com/cisco-4100-firepower-threat-defense-deploying-activestandby/
10-07-2018 03:20 AM
Thanks Again ... Its explains about the HA part and am still looking for the options to enable IPS-Only Mode
10-08-2018 01:32 AM
What you are asking about is referred to as an inline pair transparent mode deployment.
Please see the following references for implementation details:
10-08-2018 01:47 AM
10-08-2018 03:02 AM
The overall firewall can be routed or transparent.
Either way, as noted in the first link I provided: "When you configure an Inline Pair 2 Physical interfaces are internally bridged."
You're correct - they essentially act as a "bump in the wire" with IPS functionality.
10-08-2018 03:27 AM
10-08-2018 10:09 AM
Well HA gives you just that - High Availability.
As of right now we don't have the option of Fail-To-Wire (FTW) interfaces on the 2100 series. So if the single unit fails, your traffic through it will be blocked.
10-08-2018 09:53 PM
Data sheet for 2100 depicts that there is a FTW network module available for this platform . I am checking with Cisco to identify the appropriate modules.
https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw/datasheet-c78-736661.html
Also We will be deploying the Inline mode and will HA really help(will it be monitor the interface modules to initiate the failover ) . I assume we dont need any sync interface between the Pair (as its a NGIPS) and kind of lan based failover.
10-09-2018 08:34 AM
They did announce the FTW interfaces for the Firepower 2100 series but I don't believe they are shipping yet. I just checked the Cisco ordering tool and they don't show up as available in a Firepower 2140 NGFW configuration.
Building an HA pair will still require a failover link between the two appliances.
10-09-2018 09:13 AM
10-09-2018 09:17 AM
Correct the data plane interfaces don't have IP addresses in your use case.
The failover interfaces can be thought of as control plane. They will send heartbeats and other status along with configuration synchronization between the two appliances.
10-14-2018 09:02 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide