cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2181
Views
5
Helpful
5
Replies

Firepower url filtering

Hello guys,

I have recently installed a 5525x ASA with the aim of configuring url filtering and AMP, do I need to setup a FireSight Management center or can all configurations be done on ASDM? I have searched aroound and did not find any cofiguration guides on ASDM.

1 Accepted Solution

Accepted Solutions

Have you looked at the Configuration Guide? It answers all of your questions and more.

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620.html

Additionally, here are pointers to the specific bits you asked about...

Specifically, IPS and AMP are covered in the chapter on Intrusion and File Policies.

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Intrusion-Malware-Detection.html

Botnet is not a separate concept with FirePOWER but protection from Botnets is included in Cisco's Security Intelligence feeds which work in conjunction with your Intrusion Policy.

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Secint-Blacklisting.html#pgfId-1531871

URL Filtering configuration is part of an AccessControl Policy and is covered in the section on Controlling Traffic with Reputation-based Rules here:

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Rules-App-URL-Reputation.html#77351

View solution in original post

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

Most customers elect to go with FMC as it is much better at retaining historical data and reporting. If that's not important to you, you can use ASDM instead. 

You can use ASDM if you re-image the module up to version 6+. You should use the latest version 6.2 whether or not you use local (ASDM) management. You will also need the ASA at 9.5(2) or later and ASDM at 7.7(1).

For the procedure, start here:

http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/5500X/5500x_quick_start.html

Hi Marvin,

Thanks for the response, I have done the basic configs and the firepower module is also up and running. What I want is configuration guides on the following via ASDM.

- IPS

- Botnet

- URL filtering

- AMP

Regards

Tulee

Have you looked at the Configuration Guide? It answers all of your questions and more.

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620.html

Additionally, here are pointers to the specific bits you asked about...

Specifically, IPS and AMP are covered in the chapter on Intrusion and File Policies.

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Intrusion-Malware-Detection.html

Botnet is not a separate concept with FirePOWER but protection from Botnets is included in Cisco's Security Intelligence feeds which work in conjunction with your Intrusion Policy.

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Secint-Blacklisting.html#pgfId-1531871

URL Filtering configuration is part of an AccessControl Policy and is covered in the section on Controlling Traffic with Reputation-based Rules here:

http://www.cisco.com/c/en/us/td/docs/security/firepower/620/asa-fp-services/asa-with-firepower-services-local-management-configuration-guide-v620/AC-Rules-App-URL-Reputation.html#77351

Thank you Marvin,

I have managed to configure the FMC but I got an error as per attached image when I configured the management address. I tried accessing the FMC via the browser but I could not log in either. Is there any configuration that I may have skipped? I restarted the modules but still no luck.

Your FMC installation appears to be corrupted.

Can you provide more details of how you set it up - i.e., please confirm the ESXi host version, allocated hardware resources and the image file used to build the server.

Review Cisco Networking for a $25 gift card