03-28-2017 06:48 AM - edited 02-21-2020 06:02 AM
Hello guys,
I have recently installed a 5525x ASA with the aim of configuring url filtering and AMP, do I need to setup a FireSight Management center or can all configurations be done on ASDM? I have searched aroound and did not find any cofiguration guides on ASDM.
Solved! Go to Solution.
03-29-2017 01:34 AM
Have you looked at the Configuration Guide? It answers all of your questions and more.
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620.html
Additionally, here are pointers to the specific bits you asked about...
Specifically, IPS and AMP are covered in the chapter on Intrusion and File Policies.
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Intrusion-Malware-Detection.html
Botnet is not a separate concept with FirePOWER but protection from Botnets is included in Cisco's Security Intelligence feeds which work in conjunction with your Intrusion Policy.
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Secint-Blacklisting.html#pgfId-1531871
URL Filtering configuration is part of an AccessControl Policy and is covered in the section on Controlling Traffic with Reputation-based Rules here:
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Rules-App-URL-Reputation.html#77351
03-28-2017 09:37 AM
Most customers elect to go with FMC as it is much better at retaining historical data and reporting. If that's not important to you, you can use ASDM instead.
You can use ASDM if you re-image the module up to version 6+. You should use the latest version 6.2 whether or not you use local (ASDM) management. You will also need the ASA at 9.5(2) or later and ASDM at 7.7(1).
For the procedure, start here:
http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/5500X/5500x_quick_start.html
03-29-2017 12:33 AM
Hi Marvin,
Thanks for the response, I have done the basic configs and the firepower module is also up and running. What I want is configuration guides on the following via ASDM.
- IPS
- Botnet
- URL filtering
- AMP
Regards
Tulee
03-29-2017 01:34 AM
Have you looked at the Configuration Guide? It answers all of your questions and more.
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620.html
Additionally, here are pointers to the specific bits you asked about...
Specifically, IPS and AMP are covered in the chapter on Intrusion and File Policies.
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Intrusion-Malware-Detection.html
Botnet is not a separate concept with FirePOWER but protection from Botnets is included in Cisco's Security Intelligence feeds which work in conjunction with your Intrusion Policy.
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Secint-Blacklisting.html#pgfId-1531871
URL Filtering configuration is part of an AccessControl Policy and is covered in the section on Controlling Traffic with Reputation-based Rules here:
http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Rules-App-URL-Reputation.html#77351
04-04-2017 10:11 AM
Thank you Marvin,
I have managed to configure the FMC but I got an error as per attached image when I configured the management address. I tried accessing the FMC via the browser but I could not log in either. Is there any configuration that I may have skipped? I restarted the modules but still no luck.
04-04-2017 07:29 PM
Your FMC installation appears to be corrupted.
Can you provide more details of how you set it up - i.e., please confirm the ESXi host version, allocated hardware resources and the image file used to build the server.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide