cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1033
Views
10
Helpful
4
Replies

Upgrade CX to Firepower

easynet
Level 1
Level 1

Hello,

 

Currently, we use CX module for web filtering with Active Directory connection. Licenses are almost expired and the product is no longer supported so we have to upgrade it.

 

Bellow our inventory :

 

Name: "Chassis", DESCR: "ASA 5515-X with SW, 6 GE Data, 1 GE Mgmt, AC"
Name: "Storage Device 1", DESCR: "Micron 128 GB SSD MLC, Model Number: C400-MTFDDAC128MAM"

 

Module details :

 

Card Type: ASA CX5515 Security Appliance
Model: ASA CX5515
Hardware version: N/A
Firmware version: N/A
Software version: 9.3.2.1
App. name: ASA CX
App. version: 9.3.2.1

 

For other customer, we use a Firepower Mgmt. Center with ASA5508 :

 

Name: "Chassis", DESCR: "ASA 5508-X with FirePOWER services, 8GE, AC, DES"
Name: "Storage Device 1", DESCR: "ASA 5508-X SSD"

 

Module details :

Card Type: FirePOWER Services Software Module
Model: ASA5508
Software version: 6.0.1.1-24
App. name: ASA FirePOWER
App. version: 6.0.1.1-24


Is it possible to reimage the first module (on ASA CX5515) ? Or add another software module on it ?

 

Thanks in advance for your help,

 

Fiona

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes you can uninstall the CX software module and replace it with a Firepower service module. the process is described in detail here:

 

https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html

 

You will need licenses (the free control license and URL filtering at a minimum; IPS subscription strongly recommended, AMP optional) to get everything up and running with policies applied.

View solution in original post

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes you can uninstall the CX software module and replace it with a Firepower service module. the process is described in detail here:

 

https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/118644-configure-firepower-00.html

 

You will need licenses (the free control license and URL filtering at a minimum; IPS subscription strongly recommended, AMP optional) to get everything up and running with policies applied.

Thanks a lot for your quick answer Marvin,

 

 

And one last question, is it possible to backup CX Module configuration and restore on future firepower module ?

 

 

Thanks in advance,

You're welcome.

 

Re your follow-up question...

 

Unfortunately you will need to recreate all of your URL Filtering policies from scratch on the Firepower Management Center. The CX configuration has no backup-restore type of migration path to Firepower. 

Hello,

Great new ^^

Thanks a lot !

Have a nice day
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card