16-7
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 16 ASA FirePOWER (SFR) Module
Defaults for ASA FirePOWER
•
For the 5512-X through ASA 5555-X, you must install a Cisco solid state drive (SSD). For more
information, see the ASA 5500-X hardware guide. (The SSD is standard on the 5506-X.)
Additional Guidelines and Limitations
•
See
Compatibility with ASA Features, page 16-6
.
•
You cannot change the software type installed on the hardware module; if you purchase an ASA
FirePOWER module, you cannot later install other software on it.
•
You cannot configure both normal inline mode and inline tap monitor-only mode at the same time
on the ASA. Only one type of security policy is allowed. In multiple context mode, you cannot
configure inline tap monitor-only mode for some contexts, and regular inline mode for others.
Defaults for ASA FirePOWER
The following table lists the default settings for the ASA FirePOWER module.
Configure the ASA FirePOWER Module
Configuring the ASA FirePOWER module is a process that includes configuration of the ASA
FirePOWER security policy on the ASA FirePOWER module and then configuration of the ASA to send
traffic to the ASA FirePOWER module. To configure the ASA FirePOWER module, perform the
following steps:
Step 1
Connect the ASA FirePOWER Management Interface, page 16-8
. Cable the ASA FirePOWER
management interfaces and optionally, the console interface.
Step 2
(If necessary.)
Install or Reimage the Software Module, page 16-11
. Skip this step if you purchased a
model with the software module pre-installed.
Step 3
(If necessary.)
Change the ASA FirePOWER Management IP Address, page 16-14
. This might be
required for initial SSH access.
Step 4
Configure Basic ASA FirePOWER Settings at the ASA FirePOWER CLI, page 16-15
. You do this on
the ASA FirePOWER module.
Step 5
(Optional for ASA 5506-X.)
Add ASA FirePOWER to the FireSIGHT Management Center, page 16-16
This identifies the FireSIGHT Management Center that will manage the device. If you do not configure
a FireSIGHT Management Center for the 5506-X, you can manage the module using ASDM.
Table 16-1
ASA FirePOWER Default Network Parameters
Parameters
Default
Management IP address
•
System software image: 192.168.45.45/24
•
Boot image: 192.168.8.8/24
Gateway
•
System software image: none
•
Boot image: 192.168.8.1/24
SSH or session Username
admin
Password
•
System software image:
Sourcefire
•
Boot image:
Admin123
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......