03-25-2021 09:20 AM
I'm installing FTD in my network but I'd like to implement Context in FTD
I'm using FMC 6.3.0
1-FTD on ASA5516x
Model : Cisco ASA5516-X Threat Defense (75) Version 6.3.0 (Build 83)
2-FTD on ASA5516x
Model : Cisco ASA5516-X Threat Defense (75) Version 6.3.0 (Build 83)
My idea is: Clusters and Multiple contexts, I was comfortable to do it but when I'm was using Cisco ASA and Context (Failover etc) but in FTD and FMC I never did it before.
Anyone configured it before?
Thanks you
Alex Ribas
Solved! Go to Solution.
03-25-2021 10:18 AM - edited 03-25-2021 10:20 AM
Multiple context does not exist on FTD, the closest feature is multi-instance, but that is only supported on FPR-4100/9300 hardware so will not work on your ASA 5516.
Clustering is also only supported on FPR-4100/9300 hardware, so will also not work on your hardware.
Your hardware will support Active/Standby failover.
For reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster-solution.html
HTH
03-25-2021 11:18 AM - edited 03-25-2021 11:19 AM
The ASA 5516 only supports a maximum of 5 context....unless you were referring to 6 context across the 2 ASA 5516?
I don't see a reason why you need to run multiple-context. Why can you not just use one context, then you could run FTD image in HA.
03-25-2021 01:45 PM
Yes, FTD managed via FDM (local management without FMC) can authenticate to AD.
You then just create access control rules against AD users/groups with or without URL filtering
03-25-2021 10:18 AM - edited 03-25-2021 10:20 AM
Multiple context does not exist on FTD, the closest feature is multi-instance, but that is only supported on FPR-4100/9300 hardware so will not work on your ASA 5516.
Clustering is also only supported on FPR-4100/9300 hardware, so will also not work on your hardware.
Your hardware will support Active/Standby failover.
For reference:
https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/clustering/ftd-cluster-solution.html
HTH
03-25-2021 10:52 AM
So the solution in this case
Use Cisco ASA 5516-x Context(IoS) and Module Faiolver ok and
"FirePower Separate using filters integrate with FMC ? )
Any idea?
Thank you
Alex
03-25-2021 11:01 AM
You can use ASA software with FPR module managed via FMC.
03-25-2021 11:04 AM
Yes but
I have 2 Cisco ASA 5516x (6 Contexts) and one context we use to go to Internet.
My Plan is:
Profile Users Integrate Active Directory (GROUP_DIRECTOR_ FULL ACCESS) without URL Filter)
Profile Users integrate Acrive Direcgtory (GRUPO_USERS) Filter url
And user just FIrePower controller my context
It's possible?
03-25-2021 11:18 AM - edited 03-25-2021 11:19 AM
The ASA 5516 only supports a maximum of 5 context....unless you were referring to 6 context across the 2 ASA 5516?
I don't see a reason why you need to run multiple-context. Why can you not just use one context, then you could run FTD image in HA.
03-25-2021 01:34 PM
Can I use URL filter per user (Active Directory) in one context using FirePower without FMC?
Thank you.
03-25-2021 01:45 PM
Yes, FTD managed via FDM (local management without FMC) can authenticate to AD.
You then just create access control rules against AD users/groups with or without URL filtering
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide