cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1095
Views
2
Helpful
3
Replies

IPS fail-open for FTD

tato386
Level 6
Level 6

ASA with FirePower had a "fail open/close" setting to control access in case of SFR module failure.  From what I can tell, with an FTD device the IPS function is integrated into the firewall (LINA?) so is this setting NA in the FTD environment?

Thanks,

Diego

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

It is mostly not applicable with the exception of the optional network module that is available for some models that offers fail-to-wire capability. Very few customers opt for those since they are quite expensive and only available for appliance that offer a network module expansion slot.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

It is mostly not applicable with the exception of the optional network module that is available for some models that offers fail-to-wire capability. Very few customers opt for those since they are quite expensive and only available for appliance that offer a network module expansion slot.

Note the IPS-only mode for which you can do Snort fail open in software is not the mode 98% of customers are running.

Review Cisco Networking for a $25 gift card