Cisco: Security - Firepower 2100 Re-Image to ASA

  Рет қаралды 9,947

Nathan Stapp

Nathan Stapp

4 жыл бұрын

This Video documents the entire process from start of finish of Re-imaging a Firepower 2100 running Firepower Code to ASA.
00:19 Requirements
01:36 Verify Pre-Requisites
03:45 Connect to FXOS
03:52 Download Image
05:28 Verify Transfer
05:49 Start image install
06:27 Post Reboot Notes
07:53 Post install Login and verification

Пікірлер: 24
@dzl8596
@dzl8596 Жыл бұрын
Thanks for the great video Nate!! Got my upgrade started in about two minutes!
@mattraio5137
@mattraio5137 2 жыл бұрын
this works. I decided not to mess with the Filezilla and just use an USB drive.
@edmundsiew3292
@edmundsiew3292 3 жыл бұрын
Nice video, thanks. One quick question- after re-imaged to the ASA code and having configured the ASA-imaged FPR, upon reload will it be reloaded into ASA code as if it is an ASA appliance (e.g. ASA5506-X)?
@NathanStapp
@NathanStapp 3 жыл бұрын
Edmund. It depends on the code that was used for the re-image. Anything up to ASA 9.13(1) is platform mode by default. Everything after that is appliance mode by default.
@edmundsiew3292
@edmundsiew3292 3 жыл бұрын
@@NathanStapp Hi Nate, Thanks a lot for the response…. Not exact sure about the differences between Platform vs Appliance mode? Does it mean in Appliance mode, it would act just like an ASA appliance after the re-imaged without having to worry that it might go into FXOS once reloaded? We want the FPR to be exactly like a ASA appliance… Cheers….
@juanlombana821
@juanlombana821 4 жыл бұрын
How about upgrading the ASA module in the firepower 2100s? it's done from the fxos/chassis as on the 4100's?
@NathanStapp
@NathanStapp 4 жыл бұрын
Juan, I apologize for missing this earlier. The way you upgrade depends on if you are running in Appliance Mode (default for ASA 9.14+) or Platform Mode (default for ASA prior to 9.14). for Platform Mode, it is similar to the upgrade method for the 4100's, you upload an image through Firepower Chassis Manager (FCM) - web gui for FXOS, and then click upgrade. For Appliance mode it is similar to the traditional ASA upgrade method, you download an image via FTP on CLI, and change the boot pointer.
@motiamiful
@motiamiful 2 жыл бұрын
Hello Nathan, thanks for this Video... Do you happen to know if the 1100 series can also be converted from FTD to ASA? we have an 1140 ordered as FTD and we need it as ASA...
@chanpreetmangera2820
@chanpreetmangera2820 2 жыл бұрын
Yes, you can covert 1140 to ASA. Please see below link for reference. www.cisco.com/c/en/us/td/docs/security/asa/compatibility/asamatrx.html#reference_upj_nkl_x4b
@NathanStapp
@NathanStapp 2 жыл бұрын
Hey chanpreet! Thanks for responding. And Moti, as he said, yes!
@oscarportillo335
@oscarportillo335 Жыл бұрын
Hi please help .. the configuration of asa mode plataform is lost when doing upgrade IOS?
@ericmoore4515
@ericmoore4515 4 жыл бұрын
Hello. why would Engineers / companies purchase Firepower but convert it back to ASA code?
@NathanStapp
@NathanStapp 4 жыл бұрын
Hello Eric! There are a few reasons. By far the most common reason I have run into is... Its a familiar firewall! So while Firepower offers the benefit in the future of allowing deep packet inspection (NGFW) and a myriad of other benefits they can "dip their toes" so to speak by getting the hardware, and switch over later. They also generally have much better performance for the cost especially with the new 1000 series Firepower versus ASA low end series. This is just the nature of technology progressing and allowing new products with similar price points but higher performance.
@busanimthati8201
@busanimthati8201 2 жыл бұрын
True!! but instead will have firepower logically running ASA but i like the video though
@pace1134
@pace1134 3 жыл бұрын
Will this strep by step also work on the 1010 firewall ?
@NathanStapp
@NathanStapp 3 жыл бұрын
Yes in this case, the process is essentially identical, although it wouldn't hurt to post a video tutorial since I have a few sitting around....
@omarhani8118
@omarhani8118 4 жыл бұрын
Thank you for your video, but you said there is no FTD in the box just the FXOS while during the installation of the ASA image you were asked to reimage the FTD with ASA image !!
@NathanStapp
@NathanStapp 4 жыл бұрын
Hello Omar! I don't quite understand your comment but will briefly go over what happened in the video. The FPR 2100 starts with FTD (this means FTD running on FXOS - the pseudo hypervisor). I then re-imaged the box to ASA (which on the FPR 2100 means ASA running on FXOS). Both platforms still involve running FXOS it is just abstracted so most dont realize it is there. On the newer code bases you can run in what is called "appliance” mode which truly hides FXOS entirely so it would look and feel like the old ASA.
@richlee2164
@richlee2164 Жыл бұрын
@@NathanStapp Hi Nathan, I just upgrade FPR2110 to a newer version and it changes the fxos mode to appliance. Will it be fine to boot the old image in asa and revert back to the old version using platform mode.
@NathanStapp
@NathanStapp Жыл бұрын
@@richlee2164 If you actually UPGRADE the box, then the mode will be maintained. If it started in platform it will stay platform. If you re-image, then on 9.13 and above it will be appliance mode by default. On the 1000 and 2000 appliances the ASA code is packaged together with FXOS (unified code), this means if you "downgrade" the ASA code that means you will downgrade the FXOS as well. Now to answer your question, you can change the box so that is boots the old version and it will work just fine. However, I would question why you want to use platform mode. It adds additional "work" to configuration like enabling interfaces just to use and "no shut" them in ASA. Appliance mode is better in every respect.
@ushanshrestha1766
@ushanshrestha1766 3 жыл бұрын
Will it delete the all the running and startup configuration after converting to ASA?
@NathanStapp
@NathanStapp 3 жыл бұрын
Ushan, yes the running and startup configuration "get erased". I say that with quotes because the way you configure and managed FTD is completely different than ASA. There is no directly transferable version of the configuration. It would be more appropriate to say that the configuration is not compatible so cannot possibly be migrated.
@ushanshrestha1766
@ushanshrestha1766 3 жыл бұрын
@@NathanStapp Ok, that means we cannot use it in production environment.
@NathanStapp
@NathanStapp 3 жыл бұрын
Ushan, what are you trying to do specifically? we can discuss here or you can ask me directly nstapp@cisco.com
How to Convert Cisco FTD to ASA Code
7:41
LookingPoint, Inc.
Рет қаралды 7 М.
Cisco: Security - Firepower 4100 FXOS & Firmware Update
17:48
Nathan Stapp
Рет қаралды 16 М.
DAD LEFT HIS OLD SOCKS ON THE COUCH…😱😂
00:24
JULI_PROETO
Рет қаралды 14 МЛН
50 YouTubers Fight For $1,000,000
41:27
MrBeast
Рет қаралды 186 МЛН
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 16 МЛН
IPS (Intrusion Policy) with FMC - Lab || (Hacking Attack included)
16:32
Cisco: Security - Firepower Management Center (FMC) Backup
15:25
Nathan Stapp
Рет қаралды 8 М.
Installing ASA on Firepower 2100 platform
9:59
Securing Networks with Cisco Firepower Threat Defense
Рет қаралды 29 М.
Cisco: Security - Clustering a Firepower 4100 with FTD 6.3
27:32
Nathan Stapp
Рет қаралды 15 М.
Friday Firepower Hour   Intrusion and Network Analysis Policies
55:48
The Power of Firepower - Cisco Security
Рет қаралды 7 М.
This Free AI Video Tool Brings Characters to Life
10:32
Theoretically Media
Рет қаралды 10 М.
FIrepower 1010 Overview and Setup
15:16
Cisco Sal
Рет қаралды 72 М.
Cisco Firepower 2100 ASA upgrade procedure
10:25
Network Base
Рет қаралды 14 М.
PhD AI student explains how China already have won in AI..
13:28
livinlavidaluke
Рет қаралды 61 М.
DAD LEFT HIS OLD SOCKS ON THE COUCH…😱😂
00:24
JULI_PROETO
Рет қаралды 14 МЛН