Run ASA on Firepower 1010

Поделиться
HTML-код
  • Опубликовано: 26 ноя 2021
  • This video is about installing ASA software on the firepower appliance, taking a look at the ASA initial setup and then reinstalling FTD.
    Hope you enjoy
  • ХоббиХобби

Комментарии • 15

  • @ntraas1584
    @ntraas1584  2 года назад +2

    To make things easy, if you don’t want to hear my voice LOL:
    On FTD:
    Scope firmware
    Download image tftp://10.0.0.1/
    Show download-task
    Show packages
    Install security-pack version
    on ASA:
    Boot system disk0:/

  • @blakemimitz1106
    @blakemimitz1106 2 года назад +1

    Great video!

  • @xgen8k
    @xgen8k 2 года назад

    fantastic guide, thank you

  • @ABH-fh6tn
    @ABH-fh6tn Год назад

    Thank you for the video, it is very informative. just wanted to ask, what will happen to the license like AnyConnet or security plus license if it is activated in ASA and then we switch to Firepower. will it still be active?

  • @sousha6361
    @sousha6361 Год назад

    hi, which interface that i should connect to download the image?

  • @ABH-fh6tn
    @ABH-fh6tn Год назад

    Hi, have you tried to configure one of the interfaces (inside) as a switch port trunk and associate it with multiple VLANs?
    I am having an issue wherein, it will work when newly configured but will stop working after reboot. I made sure that all changes are deployed.
    I needed to change the interface to routed and then change it back to switchport trunk to make it work but again will stop working after reboot.

  • @dereklazarus7938
    @dereklazarus7938 2 года назад +1

    Question I imagine this process is the same for a FPR-4110 or 4100 Series. I also am wondering how the Migration tool will work with using another physical ASA 555X config any thoughts

    • @timhenderson895
      @timhenderson895 2 года назад

      The process is basically the same but you have an additional option when working on the chassis based fpr devices. The 4100/9300 also have the ability to be managed via the Firepower Chassis Manager. In FCM you can add an ASA logical device, both FTD/ASA are logical devices in the 4/9 series. Same as how the 1010 runs the FTD/ASA on top of fxos.
      The migration tool worked pretty well for me when I did a migration from 5545-X to FPR1120, so shouldn't have many issues with 4100. Though with IT I nearly ALWAYS have something go wrong the first time.
      Here are a couple articles that give some good information:
      www.cisco.com/c/en/us/td/docs/security/firepower/fxos/upgrade/b_FXOSUpgrade/upgrade_asa_and_fxos_on_the_firepower_4100_9300_chassis.html
      www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2019/pdf/BRKSEC-3035.pdf
      www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2018/pdf/BRKSEC-3035.pdf

  • @vijayrao7394
    @vijayrao7394 2 года назад

    Thank you for the video! Can you please make a video on installing ASDm with right version.

    • @ntraas1584
      @ntraas1584  2 года назад

      I don't currently have an ASA to show the process, though pretty simple you just upload the new ASDM image and configure it as the current through either the current ASDM or through CLI. I just uploaded a short video exploring ASA/ASDM versioning. Once I get my ASA up and running again, I can run through that.
      ruclips.net/video/GCY-gtrbHVQ/видео.html

  • @dvivcc
    @dvivcc Год назад

    Hi nTRaaS - very informative video - thank you. Question: Do you know if a license is needed in order to have "VLAN Trunk Ports" enabled on a FPR 1010?

    • @ntraas1584
      @ntraas1584  Год назад

      You don’t need any specific license to run subinterfaces (trunk ports), BUT you need to have a base license to use the firewall longer than the trial period…

    • @dvivcc
      @dvivcc Год назад

      @@ntraas1584 Got it - thank you for the follow-up.

  • @mikemcclist9997
    @mikemcclist9997 2 года назад

    Why did you do "route management" instead of "ip route" for your default route? Is that because you used EIGRP?

    • @timhenderson895
      @timhenderson895 2 года назад

      When you specify static routes on the ASA you specify the route based on the nameif which is technically a security zone. Each interface is put into a nameif and static routes specify the nameif facing that route, also, ip route doesn’t exist in ASA.
      Route management