16-4
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 16 ASA FirePOWER (SFR) Module
The ASA FirePOWER Module
Figure 16-2
ASA FirePOWER Inline Tap Monitor-Only Mode
ASA FirePOWER Passive Monitor-Only Traffic Forwarding Mode
If you want to operate the ASA FirePOWER module as a pure Intrusion Detection System (IDS), where
there is no impact on the traffic at all, you can configure a traffic forwarding interface. A traffic
forwarding interface sends all received traffic directly to the ASA FirePOWER module without any ASA
processing.
The module applies the security policy to the traffic and lets you know what it would have done if it were
operating in inline mode; for example, traffic might be marked “would have dropped” in events. You can
use this information for traffic analysis and to help you decide if inline mode is desirable.
Traffic in this setup is never forwarded: neither the module nor the ASA sends the traffic on to its
ultimate destination. You must operate the ASA in single context and transparent modes to use this
configuration.
The following figure shows an interface configured for traffic-forwarding. That interface is connected to
a switch SPAN port so the ASA FirePOWER module can inspect all of the network traffic. Another
interface sends traffic normally through the firewall.
Figure 16-3
ASA FirePOWER Passive Monitor-Only, Traffic-Forwarding Mode
A
S
A
Main
S
ystem
in
s
ide
A
S
A FirePOWER
A
S
A FirePOWER
in
s
pection
o
u
t
s
ide
VPN
Decryption
Firew
a
ll
Policy
Copied Tr
a
ffic
3
71445
Gig 1/
3
Gig 1/1
S
PAN
Port
A
S
A
Main
S
ystem
A
S
A FirePOWER
Backplane
A
S
A FirePOWER
in
s
pection
Forw
a
rded Tr
a
ffic
S
witch
40
3
42
8
in
s
ide
o
u
t
s
ide
VPN
Decryption
Firew
a
ll
Policy
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......