cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
796
Views
0
Helpful
1
Replies

Firepower 7125 questions

tahscolony
Level 1
Level 1

If I understand this correctly on this appliance, if I want to use 2 interfaces for inline IPS for the public side, I can do this, and use another interface as the span port for internal networks. Sort of like what doing contexts on the ASA's does. Is this correct?

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

You can use the interfaces thus.

It would make sense to have different polices since the passive interface (the one connected to a span port) cannot block traffic - only inform you about it.

Contexts on an ASA normally all perform the full stateful firewall functions but they are similar in that each can have a different policy and serve different purposes.

Review Cisco Networking for a $25 gift card