Cisco ASA FirePOWER ASA FirePOWER Module Configuration Guide

The ASA FirePOWER Module provides next-generation firewall services, including Next-Generation Intrusion Prevention System (NGIPS), Application Visibility and Control (AVC), URL filtering, and Advanced Malware Protection (AMP). You can use the module in single or multiple context mode, and in routed or transparent mode. It is also known as ASA SFR. To take full advantage of the ASA FirePOWER module features, do not configure ASA inspection on HTTP traffic and do not configure Cloud Web Security (ScanSafe) inspection.

PDF
Document
Cisco ASA FirePOWER Module Configuration Guide | Manualzz

Advertisement

Advertisement

/

Advertisement

Key features

  • Next-Generation Intrusion Prevention System (NGIPS)

  • Application Visibility and Control (AVC)

  • URL filtering

  • Advanced Malware Protection (AMP)

  • Inline Mode

  • Inline Tap Monitor-Only Mode

  • Passive Monitor-Only (Traffic Forwarding) Mode

  • FireSIGHT Management Center

Frequently asked questions

You can configure your ASA FirePOWER module using one of the following deployment models: inline mode, inline tap monitor-only mode, and passive monitor-only (traffic forwarding) mode. Each mode has its own traffic flow and security policy considerations.

For initial configuration, you must use the CLI on the ASA FirePOWER module. For policy configuration and management, use FireSIGHT Management Center or ASDM.

The ASA FirePOWER module and FireSIGHT Management Center require additional licenses, which need to be installed in the module itself rather than in the context of the ASA.

The ASA FirePOWER module provides more advanced HTTP inspection than the ASA, as well as additional features for other applications, including monitoring and controlling application usage. To take full advantage of the ASA FirePOWER module features, do not configure ASA inspection on HTTP traffic, Cloud Web Security (ScanSafe) inspection, and do not enable the Mobile User Security (MUS) server.

The ASA FirePOWER module does not support failover or clustering directly. When the ASA fails over, any existing ASA FirePOWER flows are transferred to the new ASA. You are responsible for maintaining consistent policies on the ASA FirePOWER modules in the high-availability ASA pair or cluster using FireSIGHT Management Center to ensure consistent failover behavior.

Preparing document for printing…
0%