16-6
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 16 ASA FirePOWER (SFR) Module
Licensing Requirements for the ASA FirePOWER Module
Compatibility with ASA Features
The ASA includes many advanced application inspection features, including HTTP inspection.
However, the ASA FirePOWER module provides more advanced HTTP inspection than the ASA
provides, as well as additional features for other applications, including monitoring and controlling
application usage.
To take full advantage of the ASA FirePOWER module features, use the following guidelines for traffic
that you send to the ASA FirePOWER module:
•
Do not configure ASA inspection on HTTP traffic.
•
Do not configure Cloud Web Security (ScanSafe) inspection. If you configure both ASA
FirePOWER inspection and Cloud Web Security inspection for the same traffic, the ASA only
performs ASA FirePOWER inspection.
•
Other application inspections on the ASA are compatible with the ASA FirePOWER module,
including the default inspections.
•
Do not enable the Mobile User Security (MUS) server; it is not compatible with the ASA
FirePOWER module.
Licensing Requirements for the ASA FirePOWER Module
The ASA FirePOWER module and FireSIGHT Management Center require additional licenses, which
need to be installed in the module itself rather than in the context of the ASA. The ASA itself requires
no additional licenses.
See the Licensing chapter of the
FireSIGHT System User Guide
or the online help in FireSIGHT
Management Center for more information.
Guidelines for ASA FirePOWER
Failover Guidelines
Does not support failover directly; when the ASA fails over, any existing ASA FirePOWER flows are
transferred to the new ASA. The ASA FirePOWER module in the new ASA begins inspecting the traffic
from that point forward; old inspection states are not transferred.
You are responsible for maintaining consistent policies on the ASA FirePOWER modules in the
high-availability ASA pair (using FireSIGHT Management Center) to ensure consistent failover
behavior.
ASA Clustering Guidelines
Does not support clustering directly, but you can use these modules in a cluster. You are responsible for
maintaining consistent policies on the ASA FirePOWER modules in the cluster using FireSIGHT
Management Center. Do not use different ASA-interface-based zone definitions for devices in the
cluster.
Model Guidelines
•
For ASA model software and hardware compatibility with the ASA FirePOWER module, see
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......