05-06-2016 12:24 PM - edited 03-08-2019 06:59 PM
This configuration example is meant to be interpreted with the aid of the documentation from the configuration guide attached to this document.
UCS-E configuration guide: http://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/e/2-0/gs/guide/b_2_0_Getting_Started_Guide.html
Firepower Virtual Appliance and Defense Center Data Sheet: https://na8.salesforce.com/sfc/p/#80000000dRH9KXPLJqkSwWBoW3e_vtLbnXOyiNg=
Firepower 3D System Virtual Installation Guide 5.3: http://www.cisco.com/c/en/us/support/security/ngips-virtual-appliance/tsd-products-support-series-home.html
FireSIGHT or Defense Center configuration guide: http://www.cisco.com/c/en/us/support/security/defense-center-virtual-appliance/tsd-products-support-series-home.html
UCS-E Troubleshooting guide: http://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/e/ts/guide/e_series_ts.html
ISR must run XE image 3.14 or above. Download here: http://software.cisco.com/download/release.html?mdfid=284389362&flowid=71903&softwareid=282046477&release=3.12.2S&relind=AVAILABLE&rellifecycle=ED&reltype=latest
Firepower virtual sensor image download here: https://software.cisco.com/download/release.html?mdfid=286259690&softwareid=286271056&release=5.3.0.8&relind=AVAILABLE&rellifecycle=&reltype=latest
FireSIGHT Management Center image download link: https://software.cisco.com/download/release.html?mdfid=286259687&softwareid=286271056&release=5.4.1.6&relind=AVAILABLE&rellifecycle=&reltype=latest
ESXi 5.0 or above. You can download VMWare customized image for Cisco here:
https://my.vmware.com/web/vmware/details?downloadGroup=CISCO-ESXI-5.1.0-GA-25SEP2012&productId=284
UCS-E140D and UCS-E160 Images: http://software.cisco.com/download/release.html?mdfid=284479266&softwareid=284480160&release=2.1.0&flowid=34485
UCS-E140S Images: http://software.cisco.com/download/release.html?mdfid=284479227&softwareid=284480160&release=2.1.0&flowid=34482
UCS-E120S Images: http://software.cisco.com/download/release.html?mdfid=286231777&flowid=50083&softwareid=284480160&release=2.2.2&relind=AVAILABLE&rellifecycle=&reltype=latest
BDI Doc in IOS-XE: http://www.cisco.com/c/en/us/td/docs/routers/asr1000/configuration/guide/chassis/asrswcfg/bdi.html
Is to implement Firepower on the UCS-E blade on ISR 4K or G2 in IPS mode using the Front Panel Port on the UCS-E blade
Firepower sensor VM requirement is 4X4X40 (4 GB RAM, 4 vCPUs and 40 GB drive space). ESXi takes up 11 GB of space. So clearly a 50 GB drive is not sufficient.
ISR Platform |
Cisco UCS EN120E |
Cisco UCS EN140N |
Cisco UCS EN120S and E140S |
Cisco UCS E140D and E160D-M2 |
Cisco UCS E160D-M1 and E180D |
1921 |
1 |
No |
No |
No |
No |
1941 |
1 |
No |
No |
No |
No |
2901 |
2 |
No |
No |
No |
No |
2911 |
2 |
No |
1 |
No |
No |
2921 |
2 |
No |
1 |
1 |
No |
2951 |
2 |
No |
2 |
1 |
No |
3925 |
2 |
No |
2 |
1 |
1 |
3945 |
2 |
No |
4 |
1 |
1 |
3925E |
1 |
No |
2 |
1 |
1 |
3945E |
1 |
No |
4 |
1 |
1 |
ISR Platform |
Cisco UCS EN120E |
Cisco UCS EN140N |
Cisco UCS EN120S and E140S |
Cisco UCS E140D and E160D-M2 |
Cisco UCS E160D-M1 and E180D |
4321 |
No |
2 |
No |
No |
No |
4331 |
No |
2* |
1 |
No |
No |
4351 |
No |
3* |
2 |
1 |
1 |
4431 |
No |
3 |
No |
No |
No |
4451 |
No |
3* |
2 |
1 |
1 |
EN140N Module should have sufficient disk drive available to install Firepower Sensor VM. We have tested with 100 GB drive.
Refer the steps here: https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200366-Configure-FirePOWER-Services-on-an-ISR-D.html#anc13
For XE image 3.14 and above CIMC should be running 2.3 or above
For ISR IOS image 15.5(1)T and above CIMC should be running 2.3 or above
Launch CIMC GUI on the browser from the laptop with the default userID and pasword.
userID: admin and password: password
Download the latest CIMC HUU and upgrade the BIOS, CIMC and other firmware components per this link: http://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/e/2-0/gs/guide/b_2_0_Getting_Started_Guide/b_2_0_Getting_Started_Guide_chapter_01010.html#task_B4052C8757D74555A073C0BD759B211D
Refer this link: https://www.cisco.com/c/en/us/support/docs/security/firepower-management-center/200366-Configure-FirePOWER-Services-on-an-ISR-D.html#anc16
Follow the above link to install the following as well:
Install VSphere Client
Setting up Firepower and FireSIGHT VMs
Configure VSwitch interfaces on ESXi
It is very important to click on properties for Vswitch1 and Vswitch2 and make sure to enable the following:
Click on the properties for the vswitch and add all vlans.
If the above is not done, then traffic will not traverse the sensor from the inside to the outside.
Spin a FireSIGHT VM and configure it
Add the FireSIGHT to the Sensor VM
Add the Sensor to the FireSIGHT
Add license to the FireSIGHT Management Center
We increase the spanning tree port cost so that the front panel port will be preferred to receive the LAN side traffic. If the Firepower VM crashes or is shut down, then, traffic will be automatically received by the router's G0/0/1 port but traffic will be processed without being scanned by the Firepower sensor VM.
Switch | Router |
Enable Rapid Spanning Tree on the Switch spanning-tree mode rapid-pvst Port connected to the UCS-E Front Panel Ge 2 Port interface GigabitEthernet1/0/1 spanning-tree cost 10
interface GigabitEthernet1/0/24 spanning-tree cost 100
|
Inside Interface Configuration no ip address here. BDI interface has the IP address interface GigabitEthernet0/0/1
We only need to vlan 200 on the outside of the sensor as only vlan 200 traffic will come in via the front panel port for inspection.
BDI Interface for vlan 100 interface BDI100
Route statements for FP-Sensor and ESXI management ip route 10.129.16.6 255.255.255.255 ucse0/1/0 |
In this example there is only one vlan traffic (200) that is sent to the sensor for inspection. In case another vlan gets added to the inside network, we need to add a corresponding BDI interface and also create a service instance on the router.
Switch#show spanning-tree vlan 100
VLAN0100
Spanning tree enabled protocol rstp
Root ID Priority 32868
Address 188b.4555.6780
This bridge is the root
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32868 (priority 32768 sys-id-ext 100)
Address 188b.4555.6780
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1 Desg FWD 4 128.1 P2p
Gi1/0/2 Desg FWD 4 128.2 P2p
Gi1/0/14 Desg FWD 19 128.14 P2p
Gi1/0/15 Desg FWD 19 128.15 P2p
Gi1/0/24 Desg FWD 4 128.24 P2p
Switch#show spanning-tree vlan 200
VLAN0200
Spanning tree enabled protocol rstp
Root ID Priority 32968
Address 188b.4555.6780
This bridge is the root
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32968 (priority 32768 sys-id-ext 200)
Address 188b.4555.6780
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1 Desg FWD 4 128.1 P2p
Gi1/0/10 Desg FWD 19 128.10 P2p Edge
Gi1/0/12 Desg FWD 4 128.12 P2p Edge
Gi1/0/13 Desg FWD 4 128.13 P2p Edge
Gi1/0/24 Desg FWD 4 128.24 P2p
Router#show spanning-tree vlan 100
G1:VLAN0100
Spanning tree enabled protocol rstp
Root ID Priority 32868
Address 188b.4555.6780
Cost 100
Port 2 (GigabitEthernet0/0/1)
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32868 (priority 32768 sys-id-ext 100)
Address 5c83.8f49.d9f2
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 0
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi0/0/1 Root FWD 100 128.2 P2p
Router#sh spanning-tree vlan 200
G1:VLAN0200
Spanning tree enabled protocol rstp
Root ID Priority 32968
Address 188b.4555.6780
Cost 10
Port 18 (ucse0/1/1)
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32968 (priority 32768 sys-id-ext 200)
Address 5c83.8f49.d9f2
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 0
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi0/0/1 Altn BLK 100 128.2 P2p
uc0/1/1 Root FWD 10 128.18 P2p
As you can see in the above output. G0/0/1 is in Altn BLK state. Packets will only come in and leave using the uc0/1/1 port which is in Root FWD state.
Switch#show spanning-tree vlan 100
VLAN0100
Spanning tree enabled protocol rstp
Root ID Priority 32868
Address 188b.4555.6780
This bridge is the root
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32868 (priority 32768 sys-id-ext 100)
Address 188b.4555.6780
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1 Desg FWD 4 128.1 P2p
Gi1/0/2 Desg FWD 4 128.2 P2p
Gi1/0/14 Desg FWD 19 128.14 P2p
Gi1/0/15 Desg FWD 19 128.15 P2p
Gi1/0/24 Desg FWD 4 128.24 P2p
Switch#show spanning-tree vlan 200
VLAN0200
Spanning tree enabled protocol rstp
Root ID Priority 32968
Address 188b.4555.6780
This bridge is the root
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32968 (priority 32768 sys-id-ext 200)
Address 188b.4555.6780
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 300 sec
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi1/0/1 Desg FWD 4 128.1 P2p
Gi1/0/10 Desg FWD 19 128.10 P2p Edge
Gi1/0/12 Desg FWD 4 128.12 P2p Edge
Gi1/0/13 Desg FWD 4 128.13 P2p Edge
Gi1/0/24 Desg FWD 4 128.24 P2p
Router#show spanning-tree vlan 100
G1:VLAN0100
Spanning tree enabled protocol rstp
Root ID Priority 32868
Address 188b.4555.6780
Cost 100
Port 2 (GigabitEthernet0/0/1)
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32868 (priority 32768 sys-id-ext 100)
Address 5c83.8f49.d9f2
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 0
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi0/0/1 Root FWD 100 128.2 P2p
Router#show spanning-tree vlan 200
G1:VLAN0200
Spanning tree enabled protocol rstp
Root ID Priority 32968
Address 188b.4555.6780
Cost 100
Port 2 (GigabitEthernet0/0/1)
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Bridge ID Priority 32968 (priority 32768 sys-id-ext 200)
Address 5c83.8f49.d9f2
Hello Time 1 sec Max Age 20 sec Forward Delay 4 sec
Aging Time 0
Interface Role Sts Cost Prio.Nbr Type
------------------- ---- --- --------- -------- --------------------------------
Gi0/0/1 Root FWD 100 128.2 P2p
uc0/1/1 Desg FWD 10 128.18 P2p
Hi Kureli,
Do you have the equivalent router and switch configuration for implementation using an ISR G2 router?
Many thanks,
Colin
Hello Kureli,
we have some 4331 router with sm-x switch modules. We have configured the internal subslot as svi and configured My question is whether I need to consider something on design guideline to connect the UCS to the internal switch or we need to some confiugration change to inspect the internal vlans traffic?
Regards,
Saimun
Can I upgrade to version 6.2.3 the NGIPSv for ISR with an UCS-E180D-M2/K9 module ?
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: