03-15-2016 11:25 AM - edited 02-21-2020 05:45 AM
Hi all,
I have a 5525x and wanted to setup the FirePower that comes with the ASA. I have read and followed the Cisco installation guide, but I am unable to access the FirePower module on the ASA. What I have done;
1. Installed FireSight Mangement --- (can ping internet, inside FW interface, and other host on a different subnet.)
2. FirePower module is configured with the same IP subnet as the inside firewall interface.
3. Management interface 'no nameif', no IP, and enabled on the same vlan as the inside interface.
FireSight Mgmt server is on VLAN101.
Management PC is on VLAN0101.
Inside FW interface is on VLAN2 (IP 192.168.2.251/24)
SFR is on VLAN2 (IP 192.168.2.249/24)
I am stuck, please help.
-Alex
03-15-2016 11:30 AM
The Firepower module uses the external physical "Management" interface on the ASA. Have you got this interface plugged in?
03-15-2016 11:33 AM
Yes, It is plugged in. Switch port is configured VLAN2. The interface status shows up/up.
03-15-2016 11:45 AM
And you have definitely loaded FirePower software onto the module, or have logged into the module to verify that there is software installed on it?
03-15-2016 11:51 AM
03-15-2016 02:18 PM
I just want to update on the issue. I have placed a test machine on the same network as the SourceFire and I was able to access it. I am still unable to access from other VLAN.
Again, I can access the Firewall from other vlan which is on the same network as the SourceFire. But, I cannot access the SourceFire.
Thanks.
03-15-2016 11:45 AM
Log is also showing denied TCP inbound connection from the module IP to the FireSight mgmt. Server. I am not sure why it's being denied. ACL for Inside interface is configured by default to permit any to the lower security zone. I have also enabled the 'enable traffic between two or more interface which are configured with same security levels'.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide