01-24-2020 06:34 AM - edited 02-21-2020 09:51 AM
We currently use a Cisco FMC 4500 6.5.02 at our Region and have ASA 5545X 9.13(1) at our branch offices.
In the ASA, under URL Filtering Servers there are Websense and Secure Computing SmartFilter radio buttons. Ideally, we would like to have the FMC at the Region be our URL Filtering Server that the ASA points to. Is this possible...???
If so, where / how do we configure in the FMC?
Thanks!
Solved! Go to Solution.
01-24-2020 01:51 PM
Your FMC can manage the Firepower service module (or, as you called it "sfr"). That module will apply URL policies if licensed and configured by the policy deployed from FMC. If the ASA is redirecting its traffic into the module it will thus apply to the traffic.
FMC, working with the module, will not do anything to affect the configuration in the ASA code portion of the appliance. It only interacts with the Firepower service module and that module doesn't change the ASA code either - it only sends a message to the ASA to drop traffic when it hits a relevant Firepower policy rule.
01-24-2020 08:59 AM
FMC only manages ASAs with respect to their Firepower service modules. So if you have a Firepower service module and the URL filtering license for it, you can configure your URL Filtering as part of the Access Control Policy associated with the Firepower service module(s).
01-24-2020 11:42 AM
Marvin,
Thanks for the info....So, is there no way to manage the ASA's with the FMC and use the FMC to push out the URL filtering to its ASA's via the SFR...??
Any information would be greatly appreciated...
01-24-2020 01:51 PM
Your FMC can manage the Firepower service module (or, as you called it "sfr"). That module will apply URL policies if licensed and configured by the policy deployed from FMC. If the ASA is redirecting its traffic into the module it will thus apply to the traffic.
FMC, working with the module, will not do anything to affect the configuration in the ASA code portion of the appliance. It only interacts with the Firepower service module and that module doesn't change the ASA code either - it only sends a message to the ASA to drop traffic when it hits a relevant Firepower policy rule.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: