EasyManuals Logo

Cisco ASA 5506-X Configuration Guide

Cisco ASA 5506-X
428 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #114 background imageLoading...
Page #114 background image
7-4
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 7 ASA FirePOWER Module
About the ASA FirePOWER Module
Figure 7-2 ASA FirePOWER Inline Tap Monitor-Only Mode
ASA FirePOWER Passive Monitor-Only Traffic Forwarding Mode
If you want to operate the ASA FirePOWER module as a pure Intrusion Detection System (IDS), where
there is no impact on the traffic at all, you can configure a traffic forwarding interface. A traffic
forwarding interface sends all received traffic directly to the ASA FirePOWER module without any ASA
processing.
The module applies the security policy to the traffic and lets you know what it would have done if it were
operating in inline mode; for example, traffic might be marked “would have dropped” in events. You can
use this information for traffic analysis and to help you decide if inline mode is desirable.
Traffic in this setup is never forwarded: neither the module nor the ASA sends the traffic on to its
ultimate destination. You must operate the ASA in single context and transparent modes to use this
configuration.
The following figure shows an interface configured for traffic-forwarding. That interface is connected to
a switch SPAN port so the ASA FirePOWER module can inspect all of the network traffic. Another
interface sends traffic normally through the firewall.
Figure 7-3 ASA FirePOWER Passive Monitor-Only, Traffic-Forwarding Mode
ASA
Main System
inside
ASA FirePOWER
ASA FirePOWER
inspection
outside
VPN
Decryption
Firewall
Policy
Copied Traffic
371445
Gig 1/3
Gig 1/1
SPAN
Port
ASA
Main System
ASA FirePOWER
Backplane
ASA FirePOWER
inspection
Forwarded Traffic
Switch
403428
inside outside
VPN
Decryption
Firewall
Policy

Table of Contents

Other manuals for Cisco ASA 5506-X

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA 5506-X and is the answer not in the manual?

Cisco ASA 5506-X Specifications

General IconGeneral
ModelASA 5506-X
Firewall Throughput750 Mbps
Maximum Firewall Connections50, 000
Maximum VPN Peers50
Integrated Ports8 x 1 GE
Stateful Inspection Throughput750 Mbps
Weight4.4 lb (2 kg)
Firewall Throughput (Multiprotocol)750 Mbps
Firewall Throughput (Application Visibility and Control AVC)250 Mbps
Concurrent Sessions50, 000
New Connections per Second10, 000
IPsec VPN Throughput100 Mbps
Interfaces8 x 1 GE
Memory4 GB
Flash Memory8 GB
Form FactorDesktop
VPN Throughput100 Mbps
Maximum Concurrent Sessions50, 000
New Sessions per Second10, 000
Operating Temperature32 to 104°F (0 to 40°C)
Storage Temperature-13 to 158°F (-25 to 70°C)
Power SupplyExternal
Humidity10% to 90% non-condensing

Related product manuals