cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2718
Views
5
Helpful
5
Replies

Limitations of FTD in Transparent Mode

animesh.mishra
Level 1
Level 1

Hi Techies, Can anyone please help on below Issue its really appreciating till now for yours entire help. "If we plant a FTD in Transparent Mode/Layer2 then what are limitation in terms of IPS/IDS, Malware and URL subscriptions. Can we still enforce the Security Features. What are other limitations" Thanks

1 Accepted Solution

Accepted Solutions

Francesco Molino
VIP Alumni
VIP Alumni
Hi

Deploying FTD in transparent mode won't remove any features from next-gen features.
Limitations are on other features.
If you implement FTD and redirect the traffic using span to monitor the traffic, there you'll have some limitations.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

5 Replies 5

If we plant a FTD in Transparent Mode/Layer2 then what are limitation in terms of IPS/IDS, Malware and URL subscriptions. Can we still enforce the Security Features. What are other limitations

 

in terms of transparent mode on FTD there is no limitation in terms of IPS/IDS, Malware and URL subscription. what model you have?

this link will tell you what are the spec.31.PNG32.PNG33.PNG

https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw/data_sheet-c78-736661.html

please do not forget to rate.

balaji.bandi
Hall of Fame
Hall of Fame

Any  transparent firewall is a Layer 2 firewall that acts like a “bump in the wire,” or a “stealth firewall,” and is not seen as a router hop to connected devices.

 

in use cases where you want to forward all the L2  traffic via FW. ( you have difficulties to change topology in exiting environment and deploy FTD inline.)

un supported features :

 

1. DHCP relay

2. routing protocol (only static allowed)

3. multicast routing.

4. QoS

5. VPN.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Francesco Molino
VIP Alumni
VIP Alumni
Hi

Deploying FTD in transparent mode won't remove any features from next-gen features.
Limitations are on other features.
If you implement FTD and redirect the traffic using span to monitor the traffic, there you'll have some limitations.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Thanks Bud

You're welcome

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Review Cisco Networking for a $25 gift card