Webcast-Deploy and Operate Cisco NGFW-FTD
Webcast-Deploy and Operate Cisco NGFW-FTD
Webcast-Deploy and Operate Cisco NGFW-FTD
Speaker name
Speaker title
Date
News &
Upcoming events
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Ask the Expert following the Webcast
http://bit.ly/ATE_NGF-FTD
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Support Community Ask the Expert
UTC (-5hrs)
http://bit.ly/sp-webcast_MRA
UTC (-3hrs)
With
Larissa Brito Insert event banner
http://bit.ly/PT_Webcast-services
With
Eduardo Moisa
Insert event banner
http://bit.ly/ATE_Cretifiaciones
Participate in Live
Interactive Technical
Events and much more
http://bit.ly/Event-Top-
Contributors
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Rate content at the Cisco Support Community
Help us to recognize the quality content in the community
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Support community Experts
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Question Manager
Adam Kilgore
Customer Support Engineer
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Thank You For
Joining Us Today!
Aastha Bhardwaj-CCIE#46900
Dinkar Sharma-CCIE#47755
19th Sep2017
1 Overview of NGFW
Installation, Licensing,
2
and Management
Agenda 3
Deployment modes,
and packet flow
Troubleshooting tools
4
demo
5 Q&A
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
What is Firepower Threat Defense?
A. Firepower(snort)
Polling Question 1 B. ASA
C. ASA + Firepower (Unified Image)
D. None of the above
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Overview
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Firepower NGFW is a complete solution
Stop more Gain more Detect earlier, Reduce Get more from
threats insight act faster complexity your network
Firepower
Firepower 9300
4100
Firepower
2100
A SA5545-
5555-X
A SA 5525-X
A SA 5506H-X
A SA 5516-X
A SA 5506W-X A SA 5508-X
A SA 5506-X
SMB & Distributed Commercial & Enterprise Data Center, High Performance Computing, Service
Enterprise Provider
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Offering extensive contextual visibility
The more you see, the better you can protect
Client applications
Operating systems
C&C
Servers
File transfers Mobile Devices
Threats
VOIP phones
1. A packet enters the ingress interface and it is handled by the ASA engine
2. If the policy dictates so the packet is inspected by the Snort engine
3. Snort engine returns a verdict (whitelist or blacklist) for the packet
4. The ASA engine drops or forwards the packet based on Snorts verdict
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Installation on ASA
*.lfbff
Boot image
*.cdisk
Images to install FTD
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on ASA
Step 1 Reload the ASA and break into ROMMON mode
Use BREAK or ESC to interrupt boot.
rommon #0>
Step 2 Configure basic network settings and install the FTD boot image
rommon 1 > ADDRESS=10.62.148.29
rommon 2 > SERVER=10.229.22.31
rommon 3 > GATEWAY=10.62.148.1
rommon 4 > IMAGE=ftd-boot-9.7.1.0.cdisk
rommon 5 > tftpdnld
Step 4 Install the system image (WITH NOCONFIRM) not to be prompted for confirmation messages during
the installation process
firepower-boot> system install ftp://10.48.45.236/ftd-6.1.0-330.pkg
Step 5 Accept End User License Agreement, specify network settings, Management mode, FTD mode
Step 6 Register FTD to FMC (if needed)
> configure manager add 10.62.148.50 cisco
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Firepower 2100 vs 4100/9300
FRR4100/9300 FPR2100
Software Separate OS images for FXOS and FTD Unified OS bundle (FTD + FXOS)
FXOS CLI Read and Configure Read-only
Management mode FMC and FCM (chassis manager) FMC or FDM
Management interface Chassis Mgmt interface for FXOS mgmt Chassis mgmt shared between
Separate interface for FTD mgmt FXOS and FTD
Syslog Syslogs for FTD ASA sent from FTD Data int FXOS and FTD ASA syslogs are
Syslogs for FXOS sent from FXOS mgmt int sent from ASA Engine
br1/management0(Snort) Diagnostic(Lina)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 1 Upload the FTD image (.csp file) to FCM (Firepower Chassis Manager)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 2 On FCM configure FTD Management and Data Interfaces (Interfaces tab)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 3 On FCM Create an FTD Logical Device (Logical Devices > Add Device)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 4 On FCM provision the FTD Management interface
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 5 On FCM provision the FTD settings (password, FW mode, DNS IP) and FMC info
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 6 On FCM provision the FTD Data interface(s)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD installation on Firepower 4100/9300
Step 7 Register FTD to FMC (Firepower Management Center)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Licensing on FTD
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Licensing
FTD uses Smart Licensing model where the license is not tied to any SN
Smart Licensing is applicable only on FTD. All other Firepower products still
use Classic Licensing
Evaluation license available for 90 days with full* functionality
After 90 days you need to register with Cisco Smart Software Manager
(CSCM)
Licensing is handled by the FMC which will not deploy or accept events from
unlicensed devices
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Licensing
To apply a Smart License on FTD
Step 1 - Obtain an ID Token from Cisco Smart Software Manager (CSCM -
Cisco License Portal)
Step 2 - Register Firepower Management Center (FMC) to CSCM
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Licensing
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Easily manage NGFWs across multiple sites
Firepower Management Center
Manage across many sites Control access and set p olicies Investigate incidents Prioritize response
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Easily manage individual NGFWs
Firepower Device Manager
Set up easily Control access and set policies Investigate incidents Prioritize response
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Firepower Threat Defense Management
FDM FMC
FMC FDM
!!! Migration between off-box and on-box will remove the whole FTD
configuration. Before migrating there is need to unregister the FTD device from
Smart Licensing server !!!
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Deployment and Interface Modes
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Deployment Scenarios
FTD can act as both NGFW and NGIPS on different network
interfaces:
NGFW derives operational modes from ASA and adds Firepower
features (Routed and Switched interface modes)
NGIPS operates as a standalone Firepower with limited ASA
engine functionality (Passive, Passive (ERSPAN), Inline pair, Inline
pair with tap interface modes)
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Pick from many deployment modes
NGIPS deployment modes NGFW deployment modes
101110
Passive
Virtual or Physical
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Deployment and Interface Modes
Deployment Modes: Interface Modes:
Routed Routed
from classic ASA
Transparent Switched (BVI)
Passive
from classic ASA
Passive (ERSPAN)
from classic
Inline Pair Firepower IPS
Inline Pair with tap
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
High Availability on FTD
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
HA Requirements
To build an HA pair between 2 FTD devices the following requirements
should be met:
Same model
Same version (FXOS and FTD)
Same number and type of interfaces
Both devices are in the same group/domain in FMC
Identical NTP configuration
No uncommitted changes on FMC
The same FTD mode: routed or transparent
No DHCP/PPPoE configured on any of interfaces
Different hostname (FQDN) for both chassis:
firepower# show chassis-management-url
https://FPR4100.cisco.com:443//
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Policy Deployment in HA
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FXOS (4100/9300) architecture and Packet Flow
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Packet Flow on FP2100
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
How can we bypass snort inspection in
FTD?
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Troubleshooting Tools
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Data-Plane - Packet-Tracer
Packet-tracer shows the ASA Engine Datapath checks done on a virtual packet
Source interface
Summary or
detailed format
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Troubleshooting Tools Capture
FTD offers 2 kinds of Captures :
1. ASA(Lina)-level capture capture command from CLISH
2. Snort-level capture capture-traffic command from CLISH
Where are these captures taking place?
IP Protocol
Circular buffer
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Logging System logs
pigtail is an FMC and FTD CLI tool that parses, reformats, and displays the
contents of several log files as the files are written
Messages shown in order based on their timestamps - Different color per file
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
FTD Debugs
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Which of the following tool is best in
troubleshooting URL filtering issue?
C. Packet tracer
D. Pigtail
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Submit Your
Questions Now!
http://bit.ly/ATE_NGF-FTD
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Collaborate within our Social Media
Twitter Facebook
@Cisco_Support Cisco Support Community
http://bit.ly/csc-twitter http://bit.ly/csc-facebook
YouTube
Ciscosupportchannel
http://bit.ly/csc-youtube
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Learn About Upcoming Events
Cisco has support communities in other languages!
If you speak Spanish, Portuguese, Japanese, Russian or Chinese we invite you to participate & collaborate
Comunidad de Soporte Cisco
De Cisco Russian
Spanish
Japanese
Comunidade de
Suporte de Cisco
Portuguese Chinese
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
More IT Training
Videos and
Technical
Seminars on the
Cisco Learning
Network
View Upcoming Sessions Schedule
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
https://cisco.com/go/techseminars
Thank you for participating, you earned a discount!
Redeem your 35% discount offer by entering code: CSC when checking out.
http://bit.ly/CSC-CiscoPress-2017
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Cisco Press
Thank you for Your
Time!
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Thanks For Joining today!
2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential