03-25-2021 09:20 AM
I'm installing FTD in my network but I'd like to implement Context in FTD
I'm using FMC 6.3.0
1-FTD on ASA5516x
Model : Cisco ASA5516-X Threat Defense (75) Version 6.3.0 (Build 83)
2-FTD on ASA5516x
Model : Cisco ASA5516-X Threat Defense (75) Version 6.3.0 (Build 83)
My idea is: Clusters and Multiple contexts, I was comfortable to do it but when I'm was using Cisco ASA and Context (Failover etc) but in FTD and FMC I never did it before.
Anyone configured it before?
Thanks you
Alex Ribas
Solved! Go to Solution.
03-25-2021 10:18 AM - edited 03-25-2021 10:20 AM
Multiple context does not exist on FTD, the closest feature is multi-instance, but that is only supported on FPR-4100/9300 hardware so will not work on your ASA 5516.
Clustering is also only supported on FPR-4100/9300 hardware, so will also not work on your hardware.
Your hardware will support Active/Standby failover.
For reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster-solution.html
HTH
03-25-2021 11:18 AM - edited 03-25-2021 11:19 AM
The ASA 5516 only supports a maximum of 5 context....unless you were referring to 6 context across the 2 ASA 5516?
I don't see a reason why you need to run multiple-context. Why can you not just use one context, then you could run FTD image in HA.
03-25-2021 01:45 PM
Yes, FTD managed via FDM (local management without FMC) can authenticate to AD.
You then just create access control rules against AD users/groups with or without URL filtering
03-25-2021 10:18 AM - edited 03-25-2021 10:20 AM
Multiple context does not exist on FTD, the closest feature is multi-instance, but that is only supported on FPR-4100/9300 hardware so will not work on your ASA 5516.
Clustering is also only supported on FPR-4100/9300 hardware, so will also not work on your hardware.
Your hardware will support Active/Standby failover.
For reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster-solution.html
HTH
03-25-2021 10:52 AM
So the solution in this case
Use Cisco ASA 5516-x Context(IoS) and Module Faiolver ok and
"FirePower Separate using filters integrate with FMC ? )
Any idea?
Thank you
Alex
03-25-2021 11:01 AM
You can use ASA software with FPR module managed via FMC.
03-25-2021 11:04 AM
Yes but
I have 2 Cisco ASA 5516x (6 Contexts) and one context we use to go to Internet.
My Plan is:
Profile Users Integrate Active Directory (GROUP_DIRECTOR_ FULL ACCESS) without URL Filter)
Profile Users integrate Acrive Direcgtory (GRUPO_USERS) Filter url
And user just FIrePower controller my context
It's possible?
03-25-2021 11:18 AM - edited 03-25-2021 11:19 AM
The ASA 5516 only supports a maximum of 5 context....unless you were referring to 6 context across the 2 ASA 5516?
I don't see a reason why you need to run multiple-context. Why can you not just use one context, then you could run FTD image in HA.
03-25-2021 01:34 PM
Can I use URL filter per user (Active Directory) in one context using FirePower without FMC?
Thank you.
03-25-2021 01:45 PM
Yes, FTD managed via FDM (local management without FMC) can authenticate to AD.
You then just create access control rules against AD users/groups with or without URL filtering
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: