cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
27234
Views
6
Helpful
17
Replies

Disabling SIP

man3mar3n
Level 1
Level 1

Hi,

 

I need to disable SIP in my FTD.

 

However, I don't have the options to issue the below command

 

configure inspection sip disable

.

I only have the below:

 

audit_cert             Change to Audit_cert Configuration Mode
configure              Change to Configuration mode
exit                   Exit Configuration Mode
expert                 Invoke a shell
history                Display the current session's command line history
kdump                  Enable or disable kernel crash dump data collection
log-events-to-ramdisk  Configure Logging of Events to disk
log-ipconnection     Configure Logging of Connection Events
logout                 Logout of the current CLI session
manager                Change to Manager Configuration Mode
network                Change to Network Configuration Mode
password               Change password
show                 Change to Show Mode
system                 Change to System Mode
user                   Change to User Configuration Mode
vmware-tools           Configure state of VMware Tools

 

Can someone enlighten me on this issue?

Thank you very much.

 

2 Accepted Solutions

Accepted Solutions

So this is ASA with FP services? You’ll need to disable SIP inspection through ASDM or ASA CLI then, not through Firepower. 

View solution in original post

17 Replies 17

k.nandakumar
Level 1
Level 1

You have to use FlexConfig in FMC to disable SIP. 

You'll find how to configure FlexConfig in below link. Have given some example. you may have to check the config to SIP. 

 

https://www.youtube.com/watch?v=OMspnE9fq08 

 

 

Regards,

Nanda 

Securing Network With Firepower Threat Defense

matty-boy
Level 1
Level 1

From the chevron '>' prompt, please show us the result from typing...

 

> configure ?

 

You should be able to disable it from command line if you wish.

 

Cheers,

Matt

Hi,

 

Below are the results from > Configure ?

 

> configure

audit_cert Change to Audit_cert Configuration Mode
kdump Enable or disable kernel crash dump data collection
log-events-to-ramdisk Configure Logging of Events to disk
log-ips-connection Configure Logging of Connection Events
manager Change to Manager Configuration Mode
network Change to Network Configuration Mode
password Change password
user Change to User Configuration Mode
vmware-tools Configure state of VMware Tools

 

 

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi,

Go to FTD clish

> configure inspection sip disable

will help you to disable sip inspection.

 

HTH

Abheesh

Hi,

 

That is what Cisco manual says as well.

But I don't see the option in the FTD clist.

I only see the below :

 

> configure

audit_cert                           Change to Audit_cert Configuration Mode
kdump                                 Enable or disable kernel crash dump data collection
log-events-to-ramdisk        Configure Logging of Events to disk
log-ips-connection             Configure Logging of Connection Events
manager                             Change to Manager Configuration Mode
network                              Change to Network Configuration Mode
password                            Change password
user                                    Change to User Confiuration Mode
vmware-tools                     Configure state of VMware Tools

 

Please post output from > show version

Hi,

 

Below are my > sh version

 

> show version
-----------------[ xxxx-Firepower ]-----------------
Model                     : ASA5515 (72) Version 6.2.2 (Build 81)
UUID                      : 5795d1ba-741e-11e8-898d-dcdefb6d8f3b
Rules update version      : 2016-11-29-001-vrt
VDB version               : 271
----------------------------------------------------

Weird. Are you logged in as a user with full admin rights?

Hi,

 

I logged in as admin.

 

There is only 1 user which is admin.

are you managing this with FDM or FMC. If FMC you can do this via Flex config

Create a Flex Config Object and enter below command

policy-map global_policy
class inspection_default
no inspect sip

Then bind this Flex object to Flex Policy.

 

HTH

Abheesh

Hi,

 

I don't have FMC.

 

The firewall is with ASDM.

 

 

So this is ASA with FP services? You’ll need to disable SIP inspection through ASDM or ASA CLI then, not through Firepower. 

Hi,

 

Yes, this is ASA 5515x with Firepower Services.

 

I already disable it in ASA.

 

So that should be fine.

 

Thanks.

Review Cisco Networking for a $25 gift card