06-03-2018 07:52 AM - edited 02-21-2020 07:50 AM
I try to deploy ASA 5525-X with FirePOWER is managed by FMC (with license AMP).
I want to control malware or file in my network. This is my steps to deploy:
- Deploy FMC in VMware
- Register ASA 5525-X with FirePOWER is managed by FMC
- Register license to FMC and assign license to managed device.
- Create Malware and File Policy and specify it in an access policy -> click Deploy.
Can I block malware or file with previous steps ? What is recommended for this case ?
I wonder :
- I can create Intrusion Policy or not with these license ?
- If I can create Instruction Policy, I should create Intrusion Policy or not in this case?
Information about ASA 5525-X with FirePOWER
ASA 5525-X with FirePOWER Svcs | 1 | |
ASA5525-FPWR-BUN | ASA 5525-X with FirePOWER Svcs. Chassis and Subs. Bundle | 1 |
ASA5525-FPWR-K9 | ASA 5525-X with FirePOWER Services, 8GE, AC, 3DES/AES, SSD | 1 |
CON-SMBS-A25FPK9 | CSCO SUP ESS 8X5XNBD ASA 5525-X with FirePOWER Services, 8GE | 1 |
CAB-ACE | AC Power Cord (Europe), C13, CEE 7, 1.5M | 1 |
SF-ASA-X-9.8.2-K8 | Cisco ASA 9.8.2 Software image for ASA Spyker/Saleen | 1 |
SF-ASA-FP6.2.2-K9 | Cisco FirePOWER Software v6.2.2 for ASA 5500-X | 1 |
ASA5525-CTRL-LIC | Cisco ASA5525 Control License | 1 |
ASA-IC-B-BLANK | ASA 5525-X Interface Card Blank Slot Cover | 1 |
ASA5500X-SSD120INC | ASA 5512-X through 5555-X 120GB MLC SED SSD (Incl.) | 1 |
ASA5525-MB | ASA 5525 IPS Part Number with which PCB Serial is associated | 1 |
ASA5500-ENCR-K9 | ASA 5500 Strong Encryption License (3DES/AES) | 1 |
FS-VMW-2-SW-K9 | Cisco Firepower Management Center,(VMWare) for 2 devices | 1 |
CON-ECMU-VMWSW2 | SWSS UPGRADES Cisco Firepower Management Center,(VMWare) for | 1 |
L-ASA5525-AMP= | Cisco ASA5525 FirePOWER AMP License | 1 |
L-ASA5525-AMP-1Y | Cisco ASA5525 FirePOWER AMP 1YR Subscription | 1 |
Solved! Go to Solution.
06-03-2018 08:08 AM
Since you've not purchased the IPS subscription / license, you have no right-to-use the IPS feature. That particular one is not enforced via technical means so the system won't stop you from doing so. However you would be violating the End User Licensing Agreement (EULA).
06-03-2018 08:08 AM
Since you've not purchased the IPS subscription / license, you have no right-to-use the IPS feature. That particular one is not enforced via technical means so the system won't stop you from doing so. However you would be violating the End User Licensing Agreement (EULA).
06-03-2018 08:41 AM
Hi Marvin,
I can control malware or file with these previous steps?
Do you have any other recommed in my case (control malware or file) ?
Thank you for your helps in advance.
06-04-2018 08:24 AM
Sure - a file policy will control malware transiting the firewall. Not all file types are supported but the most common ones are.
An effective Malware defense combines security at the edge (AMP on your NGIPS / firewall) with endpoint protection (i.e. AMP for Endpoints). Not all Malware comes through the "front door" (your firewall) and endpoint-based protection covers a lot of other scenarios.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide