cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3547
Views
10
Helpful
7
Replies

License required for Firepower module services

Hello Experts @Marvin Rhoads  @Rob Ingram  @balaji.bandi 

 

They got multiple licenses like Malware (AMP), URL, Malware, Base.

Need to know which one is required for Geo-Blocking ? and blocking multiple domains like xyzlawyers.com etc

also, what does Base license means?

 

Also, Is there any way to block Applications like we do on Fortigate, like Application Control, which license is required for that?

 

Thanks,

LJ 

3 Accepted Solutions

Accepted Solutions

@LovejitSingh130013 

Base is the license that comes with the device and does not require a subscription.

Here is a break down of the features per license:

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/licensing_the_firepower_system.html

 

View solution in original post

balaji.bandi
Hall of Fame
Hall of Fame

check base License here :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Licensing_the_Firepower_System.html

 

with IPS you can block geo-based ( make sure you get geo database updated periodically)

 

If you know the IP address range, you can directly block using ACP

 

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Whether you need Smart or Classic licenses depends on the type of devices you are managing.

ASA Firepower service modules use classic licenses. They start with Control + Protect (Free) and add on IPS subscription, Malware and URL Filtering (all paid).

FTD devices (running on either Firepower appliances, VMs or ASA hardware) use smart licenses. They start with Base (free) and add on Threat, Malware and URL Filtering (all paid).

View solution in original post

7 Replies 7

@LovejitSingh130013 

Base is the license that comes with the device and does not require a subscription.

Here is a break down of the features per license:

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/licensing_the_firepower_system.html

 

Thanks @Rob Ingram  

 

When I need to purchase the Smart license, just it needs to purchase with Sfr serial no. or ASA serial no.

 

Also, My FMC is not even showing Base as licensed. is it normal or it needs some work.

 

ASA.JPG

Whether you need Smart or Classic licenses depends on the type of devices you are managing.

ASA Firepower service modules use classic licenses. They start with Control + Protect (Free) and add on IPS subscription, Malware and URL Filtering (all paid).

FTD devices (running on either Firepower appliances, VMs or ASA hardware) use smart licenses. They start with Base (free) and add on Threat, Malware and URL Filtering (all paid).

balaji.bandi
Hall of Fame
Hall of Fame

check base License here :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Licensing_the_Firepower_System.html

 

with IPS you can block geo-based ( make sure you get geo database updated periodically)

 

If you know the IP address range, you can directly block using ACP

 

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello @Marvin Rhoads  @balaji.bandi @Rob Ingram 

 

Does TC (Threat + URL) will be enough to perform Geo-blocking?

 

Thanks,

 

LJ

@LovejitSingh130013 yes it will suffice.

yes that should work (if you not able to use ACP to block)

 

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card