View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

SEC0158 - ASA FirePower Service Installation

Rating: 
5
Average: 5 (7 votes)
Difficulty Level: 
0
Lab Document: 
<Please login to see the content>
The video gets you started on software installation of Cisco ASA FirePower service module and prepare it to be a managed device that will be added later to a FireSight system. The lab assumes no existing FirePower software installation or that you want to replace the previous IPS or CX services on the ASA.
 
Topic:
  • ASA FirePower Software Service
  • ASA FirePower boot and software image
  • ASA FirePower setup wizard

About Author

Metha Chiewanichakorn, CCIE#23585 (Ent. Infra, Sec, SP), is a Cisco networking enthusiast with years of experience in the industry. He is currently working as a consulting engineer for a Cisco partner. As a founder of and an instructor at labminutes.com, Metha enjoys learning and challenges himself with new technologies.

25 comments

Excellent presentation of a Net New or pre-installed ASA.

Not sure is this is also a Q&A??? I was wondering when in a dual ASA (Active/Failover) environment would the MGMT0 interface be configured with 'standby' as is other interfaces. For example (mgmt0 ip address 192.168.1.1 standby 192.168.1.2) If so, then mgmt0's would require a switch for access to Defense Center ??

All in all, some of the best presentations around !!!
Thanks much

If you don't plan to use the mgmt interface to manage the ASA, you don't really need to give it an IP. The SFR is just riding on the mgmt interface but its IP is actually configured on itself so if you have a failover pair, you would configure the SFR IP individually.

so, I am not using the MGT interface on the ASA, how will I access the source fire ? using the inside IP address ?, also when entering the Setup on the bootstrap of the source fire, if I don't enter YES to use the management interface, no IP shows on the summary.
please advise.

Mgmt interface is required for Firepower so at minimum, you need that port connected to a switch. You then have a option whether to use mgmt interface for the ASA. If you do, the IP need to be on the same subnet as the FirePower, otherwise you don't need to do anything on the ASA

Hi

did we still need DC to mange the IPS SFR or we can mange this IPS from ASDM

As of now, FireSight server is required to manage FirePower Devices.

Thanks for the videos! I created a config script to go along with the video that I will be using for installs... thought I would share.

http://4peg.com/gGlqMN1dNCHw?FirePOWER%2BBoot%2BImage=asasfr-5500x-boot-...

Thank you for sharing!!

Thanks for sharing the script. I have an install in 2 weeks and was creating a script. Seen yours and compared it.. Seems like the script hits the nail on the head.

thank you for a great video

Thank you for your feedback. We are glad you enjoy our videos.

can we direct traffic to ASA FirePower service module without pathing in ASA

Not sure what you mean. The traffic needs to enter ASA in order to be sent to FirePower. What are you trying to accomplish?

i need to enter traffic to firepower without passing on asa , use ports to pass trafice to firepower only like using appliance

If you want to SPAN traffic to ASA Firepower, you can use the following commands. The SPAN traffic goes to Gi0/0 of the ASA. Configure FirePower as you would normally.

config t
firewall transparent
int m0/0
  ip address <ASA Management IP> <Netmask>
  route management 0 0 <GW IP>
int g0/0
  traffic-forward sfr monitor-only
write memory

Thank you for your time :)

Dear Metha,
Have you any video for integration BTW SourceFire and ISE.
BR

We do but it is not released online yet. Please visit our store and search for SEC0222.

I got an error saying

113
Upgrade Aborted

Has anyone faced similar issue?
Is there a workaround for this?

Is this a fresh install? What version and hardware are you using? At which point did you encounter the error?

will FirePower Services run on Virtual Machine Lab ?

Yes. You have two options: NGIPSv which is a sensor with Firepower feature only and not routed, or FTDv which can either be a just a sensor or fully function ASA+Firepower FW.

thanks for producing and making these videos available to us.

Thank you very much for your feedback

Hi
Are there English translation files (.srt) for these videos ?
Thanks in advance