06-15-2019 07:47 PM
This is great for ASA sizing
Specifically showing the serialisation of all possible filters/engines (fundamentally and mathematically appropriate as it slows down the deeper the inspection/parsing/extraction goes.. this is critical for me to see.)
Do we have anything for FP NGIPS appliances ?
(Could probably HTTP parameter 'hack' the https://apps.cisco.com/ccw/cpc/compare/ucsComparePage page to add the selected values for FP appliances ?)
Solved! Go to Solution.
06-16-2019 07:51 PM
Cisco recommends we use this tool for FTD/NGFW:
The output is not as verbose; but they have consistently declined to make a more comprehensive tool available - even to partners.
06-16-2019 07:51 PM
Cisco recommends we use this tool for FTD/NGFW:
The output is not as verbose; but they have consistently declined to make a more comprehensive tool available - even to partners.
06-16-2019 08:53 PM
The output is not as verbose; but they have consistently declined to make a more comprehensive tool available - even to partners.
< sad face >
06-16-2019 09:24 PM
If you pick 5Gb+ for bandwidth profile and have all engines/filters ticked except for the last one, being VPN (aka, all prior checkboxes..).
Do you get any options ? (Common packet profile and 40-80% uti)
:/
06-16-2019 11:09 PM
It gives no options. :/
SSL decryption is the killer. Cisco (nor most others) won't commit to (or recommend) trying to do SSL decryption at full line rate for that high of throughput.
That said, they have tweaked SSL decryption performance for some of the more recent releases (introduced in hardware as of 6.2.3 and on by default in 6.3 and 6.4) and the tool might not yet reflect that.
I'd check directly with your Cisco SE if high throughput SSL decryption is important to you. Other security options (WSA, Umbrella, ETA etc.) may be more architecturally appropriate to address the underlying security need.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide