cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2847
Views
0
Helpful
5
Replies

ASA FirePower Passive Monitor-Only

cofee
Level 5
Level 5

Hello,

 

Is there any possibility to configure a traffic-forwarding interface and connect it to a SPAN port on a switch when ASA with FirePower module is configured in routed mode? Is there any workaround?

 

 

Thanks!

2 Accepted Solutions

Accepted Solutions

mikael.lahtela
Level 4
Level 4
Hi,

If you are going to follow the guides you need to have the ASA in transparent mode to listen to a SPAN port.
The connection needs to be established in routed mode before it is sent to the ASA Firepower module.
Don't think there is a workaround for this.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.pdf

br, Micke

View solution in original post

Julio Carvajal
VIP Alumni
VIP Alumni

Hi,

 

Unfortunately No.

 

You have to run it in Transparent mode in order to make this happen.

 

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

5 Replies 5

mikael.lahtela
Level 4
Level 4
Hi,

If you are going to follow the guides you need to have the ASA in transparent mode to listen to a SPAN port.
The connection needs to be established in routed mode before it is sent to the ASA Firepower module.
Don't think there is a workaround for this.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-firewall-cli/modules-sfr.pdf

br, Micke

Julio Carvajal
VIP Alumni
VIP Alumni

Hi,

 

Unfortunately No.

 

You have to run it in Transparent mode in order to make this happen.

 

Regards

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks for the response. I have a spare asa 5510 with an IPS module (ssm 10), is it possible to configure this firewall for SPAN and analyze traffic using IPS/IDS module?

Hey Coffee,

 

no, the only way to redirect the traffic is from the ASA itself (on this model).

 

 

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks everyone!
Review Cisco Networking for a $25 gift card