collapse

Search


User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Author Topic: Cisco ASA with FirePOWER  (Read 27339 times)

Offline amsa

  • Cisco Newbie
  • *
  • Posts: 32
  • Reputation: 0
  • Certification: CCNA
Cisco ASA with FirePOWER
« on: July 11, 2015, 09:28:20 AM »
Hi all,

My company is ready to deploy demo ASA with firepower, I have some questions about that,

what is the technical issues we will meet if we upgrade our ASA to FP and which the rollback steps after  the end of the demo?

ASA with firepower can be support about 4000 concurrent session (integrate with Active Directory) ? & support Single sign on ?

can we management for user ?

how to URL filtering categories ?

Which feature not found in ASA with firepower and exists in WSA ?  i.e, Cisco ASA with FirePOWER can replace WSA In all the functions?


please help me

thanks,

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: Cisco ASA with FirePOWER
« Reply #1 on: July 11, 2015, 05:37:14 PM »
Please keep in mind the FP and ASA are two logically separate device even though FP is physical hosted inside an ASA as a software service or hardware module. Upgrading ASA to 5500X model is the prerequisite. After that FP can be installed and you are free to whether or not redirect traffic from ASA to FP.
Please check the datasheet on the FP capacity per the model you have.
Not sure what you mean by single-sign-on. FP/Firesight relies on username-to-IP mapping provided by the SourceFire User Agent and allows you to use user or usergroup in access-control list so user does not actually need to perform additional authentication.
URL filtering by category is supported with URL license.
One main difference is FP does not function as web proxy/cache or support WCCP like WSA.

Offline amsa

  • Cisco Newbie
  • *
  • Posts: 32
  • Reputation: 0
  • Certification: CCNA
Re: Cisco ASA with FirePOWER
« Reply #2 on: July 11, 2015, 10:25:09 PM »
Thanks a lot MC,

and , you can prevent one user from different addresses in ASA FP ?

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: Cisco ASA with FirePOWER
« Reply #3 on: July 13, 2015, 05:30:33 AM »
Could you please elaborate on your question?

Offline amsa

  • Cisco Newbie
  • *
  • Posts: 32
  • Reputation: 0
  • Certification: CCNA
Re: Cisco ASA with FirePOWER
« Reply #4 on: July 15, 2015, 02:46:48 AM »
Ok
How can one ensure single logon for AD users, Situation exist where one users open multiple login session on different computer?  Can we control that by Cisco ASA with FirePower ?

another question please  :)
ASA with firepower is mandatory (stop video, social media, anonymous proxies, tunneling softwares (ex. TOR, Ultra surf, etc.)?


thanks,



Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: Cisco ASA with FirePOWER
« Reply #5 on: July 15, 2015, 05:50:54 AM »
FirePower cannot enforce user to only have single session although it will be able to track all the IPs the user are coming from via Sourcefire User Agent and enforce access-control properly.
Any application filtering capability requires FirePower with Control (AVC) license.

Offline amsa

  • Cisco Newbie
  • *
  • Posts: 32
  • Reputation: 0
  • Certification: CCNA
Re: Cisco ASA with FirePOWER
« Reply #6 on: July 20, 2015, 07:48:48 AM »
thanks alot MC

 

Related Topics

  Subject / Started by Replies Last post
1 Replies
28122 Views
Last post May 15, 2015, 05:55:19 AM
by MC
2 Replies
25635 Views
Last post June 21, 2015, 11:29:09 AM
by misthe
1 Replies
24405 Views
Last post August 29, 2015, 05:19:33 PM
by MC
2 Replies
35183 Views
Last post November 02, 2015, 06:56:59 AM
by chhayheng
1 Replies
35868 Views
Last post November 06, 2015, 04:57:48 PM
by MC

SimplePortal 2.3.7 © 2008-2024, SimplePortal