1- FMC - FTD
1- FMC - FTD
1- FMC - FTD
• The new Adaptive Security Appliance (ASA), called Firepower Threat Defense (FTD).
• History of SourceFire/Firepower
• Sourcefire was founded in 2001 by Martin Roesch, the creator of Snort.
• The company created a commercial version of the Snort software, the Sourcefire 3D System, which
evolved into the company’s Firepower line of network security products.
• Sourcefire was acquired by Cisco for $2.7 billion in July 2013.
• In early 2012, Sourcefire introduced version 5 of the “SourceFire System.”
• When you see FirePOWER , it’s almost always used to describe "FirePOWER Services on ASA."
• This could mean software services, or the FirePOWER blade installed on the ASA 5585-X.
• The "Firepower System" is the new Cisco IPS
• Managing Firepower
• There are many ways to manage your Firepower appliances and/or FTD
- Firepower Device Manager (FDM)
- Firepower Management Center (FMC)
- Cisco Defense Orchestrator (CDO)
- Adaptive Security Device Manager (ASDM)
SNCF Page 1
no FMC available.
SNCF Page 2
•
our small to large ASA deployments.
• ASDM provides some of the configuration and management capability of FirePOWER.
• Whether you have a Firepower appliance (7000/8000), ASA with a FirePOWER module, or an FTD
device, the Snort engine is basically the same for all models and configured mostly the same way
through the FMC.
SNCF Page 3
information.
• Virtual FMCs
• The original version, managed up to 25 devices.
• The new virtual FMC that runs in beast mode, managing up to 300 devices!
• Install the FMC
SNCF Page 4
SNCF Page 5
• Log in with the default credentials:
- Username: admin
- Password: Admin123
• Hardware FMCs
• The FMC will only have management interfaces. (FMC doesn’t actually do any detection itself).
• The primary management port for all of the hardware FMCs is eth0, and you can use eth1, eth2, and
eth3 as secondary management or event ports.
SNCF Page 6
• There are three options available to access the console:
- Connect a USB keyboard and VGA monitor.
- Connect to the serial console port.
- Connect via SSH to the default IP address of 192.168.45.45
SNCF Page 7
• Run the configure network script with the following command:
> expert
> sudo /usr/local/sf/bin/configure-network
Password:
Do you with to configure IPv4 (y or n) y
Management IP address? 172.16.10.20
Management netmask? 255.255.255.0
Managmeent Default gateway? 172.16.10.1
Are these settings correct? (y or n) y
Do you wish to configure IPv6 (y or n) n
Updated network configuration.
Please go https://172.16.10.20/ to finish installation.
SNCF Page 8