cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1642
Views
0
Helpful
8
Replies

NextGen IPS firepower appliances deployment with multitenancy support

osi_badran
Level 1
Level 1

Dears,

i have a concern regarding deploying and designing firepower next generation IPS appliances 8250 in multi-tenancy deployment, as i need to have inline IPS appliance running in two different zones (edge and DC), at the same time to have higher bandwidth with selecting correct type of interfaces to be BP or NBP for this setup to utilize this high IPS bandwidh around 10G !

second point: what are the options of building redundant IPS solution ? so no single point of failure !

Thanks all.

1 Accepted Solution

Accepted Solutions

The NGIPS appliance itself does not support multi-tenancy cleanly. You can have different policies on different interface pairs of a given sensor but that sensor can only belong to a single domain.

You can use the Domain Management feature of FirePOWER Manager 6.0 to segregate your tenants' access across different managed devices:

http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Domain_Management.html

View solution in original post

8 Replies 8

Philip D'Ath
VIP Alumni
VIP Alumni

thanks its a nice video but all about ACI automation and integration with security overview, not about firepower NGIPS solution .

anyway i think as per some researches that NGIPS doesn't support multiple contexts or multi tenants as cisco IPS can do with virtual sensors ! i need to confirm this information

as well i found stacking doesnt provide HA over single point of failure, its only adding devices  processors to the cluster connected to primary unit by stacking connectors back to back  !

The NGIPS appliance itself does not support multi-tenancy cleanly. You can have different policies on different interface pairs of a given sensor but that sensor can only belong to a single domain.

You can use the Domain Management feature of FirePOWER Manager 6.0 to segregate your tenants' access across different managed devices:

http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Domain_Management.html

What about FP Manager 5.4 ? does it support the same ?

No. The domain feature for multitenant support is new as of FP Manager 6.0

You can put the ASA in multiple context mode and SFR for each independently. 

Collin,

I believe the FirePOWER module still is limited to a single Policy Set (and/or Domain when using the 6.0-or later feature) even though the base ASA is in multiple context mode.

The module has no awareness of the ASA's context configuration.

What about FP Manager 5.4 ? does it support the same ?

Review Cisco Networking for a $25 gift card