Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

New SourceFire IPS for ASA firewalls

I am in the process of ordering numerous ASA firewalls up to the 5585X models complete with IPS

 

I just found out that Cisco is now using SourceFire/Firepower for these, and is probably going to discontinue the old system.

 

I don't see a whole lot of documentation on this new system, and many of the links on the Cisco website simply link back to the old Sourcefire company page. So I had some general questions

 

1. How radically different is the new IPS/IDS system? Is it still based on signatures, threat ratings, etc.?

2. Where can I go to find documentation on this? Any books? PDFs?
3. How long has this been out? Has it been real-world tested?

4. can I manage these IPS systems with IME, or do I need new software? What about ASDM?

1 REPLY
VIP Purple

> I just found out that Cisco

> I just found out that Cisco is now using SourceFire/Firepower for these, and is probably going to discontinue the old system.

The legacy IPS is already announced for EOS/EOL.

> 1. How radically different is the new IPS/IDS system? Is it still based on signatures, threat ratings, etc.?

It's still mainly a signature-based system, more or less same as before. Expect an easier tuning and better defaults then before.

> 2. Where can I go to find documentation on this? Any books? PDFs?
Not that easy, Beside the infos on the cisco website the are also trainings like the SASAA 1.2 that start to integrate FirePower. But there it's only one topic of many.

> 3. How long has this been out? Has it been real-world tested?

As an IPS it probably deserves the status "real-worls tested". As a cisco-integrated system, well, I would say it's on the way.

> 4. can I manage these IPS systems with IME, or do I need new software? What about ASDM?

no IME any more! You use the FireSight Management-Center (appliance or VM). I heard that ASDM-integration is planned, but I wouldn't expect that anytime soon.

--
Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
278
Views
0
Helpful
1
Replies