Deploy Cisco FirePOWER Management Center (Appliance)
Nov30

Deploy Cisco FirePOWER Management Center (Appliance)

KB ID 0001263 Dtd 30/11/16 Problem You have been able to manage your firewalls Internal SFR module for ¬†while using the ASDM Setup FirePOWER Services (for ASDM) For most people that’s fine, but if you have a lot of FirePOWER devices to manage that does not scale well. In those cases you should use theFMC ¬†(FirePOWER Management Center). Here ‘Im going to use the Vmware virtual appliance, (at time of writing there is no...

Read More
Cisco FirePOWER User Agent – Use With the FirePOWER Management Console
Apr27

Cisco FirePOWER User Agent – Use With the FirePOWER Management Console

KB ID 0001179 Dtd 27/04/16ProblemFirePOWER Management Center, will give you a wealth of information on traffic/threats etc. Usually it will tell you what IP the offenders are on, but if you want to know what a USER is doing, then that means you have to look though logs see who had what IP, at what time etc.So you can install the FirePOWER User Agent on a machine, (this can be a client machine, though I usually put it on a member...

Read More
Cisco Add FirePOWER Module to FirePOWER Management Center
Apr25

Cisco Add FirePOWER Module to FirePOWER Management Center

KB ID 0001178 Dtd 25/04/16ProblemIf you only have one FirePOWER service module you can now manage it from the ASDM;ASA 5505-X / 5508-X Setup FirePOWER Services (for ASDM)But if you have got more than one, and you can manage them centrally with the FirePOWER Management Center, (formally SourceFIRE Defence Center). WARNING:  If you are going to use FMC DON'T register your licences in the ASDM, they all need to be registered in the...

Read More
Cisco Firepower Services – Change IP and DNS Addresses
Apr07

Cisco Firepower Services – Change IP and DNS Addresses

KB ID 0001173 Dtd 07/04/16 Problem If you change your internal LAN addresses its easy to re-ip the firewall but what about the FirePOWER module? If you manage your SFR from the ASDM it will tell you what the IP is, but it won't let you change it?   Solution Change the FirePOWER Module IP Address Log into the firewall, then open a session with the SFR module. find the physical address of the module (usually eth0, but check). Petes-ASA#...

Read More
Cisco FirePOWER – Update Fails ‘Peer Registration Failed: Registration in Progress’
Mar02

Cisco FirePOWER – Update Fails ‘Peer Registration Failed: Registration in Progress’

KB ID 0001162¬†Dtd¬†02/03/16 Problem If you attempt to perform an update on the FirePOWER services module in your firewall, you may see the following error; Error Installation Failed: Peer registration in progress. Please retry in a few moments I found myself in this situation because I’d attempted to register the firewall in the FirePOWER Management Center Appliance, and the process failed, (because the versions were different)....

Read More
FireSIGHT (SourceFire) – AMP Malware Inspection
Feb15

FireSIGHT (SourceFire) – AMP Malware Inspection

KB ID 0001159 Dtd 15/02/16 Problem If you take a look in your SourceFire dashboard, and there is no data shown on the malware threat section like so; Solution The message is pretty descriptive, and it’s telling you exactly what you need to do. Now I’m making the assumption that you have added a valid AMP / Malware licence like so; Policies > Access Control > Edit your access control policy > Then Edit the file...

Read More