Just an FYI the new firepower ASAs have been announced

Started by dlots, February 19, 2016, 10:09:59 AM

Previous topic - Next topic

dlots

The new FirePowers have been announced and they are moving the ASA feature set into them, very limited feature set at the moment though (hope you don't want things like EIGRP, or VPN capabilities).  They are monster boxes to at ~20Gb for the smallest one.  No management will be done on them, all management is done at the Firepower Management Center thingy (no more CLI or ASDM).  Also my understanding is that they will run as a VM.

http://www.cisco.com/c/en/us/products/security/firepower-4100-series/index.html

deanwebb

Interesting. Do they ship pre-patched for the ASA vulnerabilities?
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

mmcgurty

Quote from: deanwebb on February 19, 2016, 11:29:01 AM
Interesting. Do they ship pre-patched for the ASA vulnerabilities?

Doubtful.  More than likely it will contain more vulnerabilities/bugs that you will bug test for them.

Otanx

The datasheet shows throughput numbers for VPN/IPSec so it looks like it will do that at least. I would love to play with a couple of these, but I don't want to be the first one running them in production.

datasheet - http://www.cisco.com/c/en/us/products/collateral/security/firepower-4100-series/datasheet-c78-736661.html

-Otanx

deanwebb

We might get to be among the first at a few sites...
Take a baseball bat and trash all the routers, shout out "IT'S A NETWORK PROBLEM NOW, SUCKERS!" and then peel out of the parking lot in your Ferrari.
"The world could perish if people only worked on things that were easy to handle." -- Vladimir Savchenko
Вопросы есть? Вопросов нет! | BCEB: Belkin Certified Expert Baffler | "Plan B is Plan A with an element of panic." -- John Clarke
Accounting is architecture, remember that!
Air gaps are high-latency Internet connections.

wintermute000

2 Maximum throughput with User Datagram Protocol (UDP) traffic measured under ideal test conditions.

HA! Let the firewall spec wars and vendor test methodology accusations begin anew. *cough fortinet numbers cough*

seriously though, its a bit strange how there's no low-mid level offerings (around the 1Gb throughput range) to compete around the SRX340, PA-3020, Fortinet 500D etc. arena.

Reggle

The Fortinet numbers really are that good. Unless you check *any* kind of NGFW-functionality...

NetworkGroover

Quote from: mmcgurty on February 19, 2016, 11:49:10 AM
Quote from: deanwebb on February 19, 2016, 11:29:01 AM
Interesting. Do they ship pre-patched for the ASA vulnerabilities?

Doubtful.  More than likely it will contain more vulnerabilities/bugs that you will bug test for them.

Heh heh heh  :problem?:
Engineer by day, DJ by night, family first always

Otanx

Quote from: wintermute000 on February 23, 2016, 03:50:16 AM
seriously though, its a bit strange how there's no low-mid level offerings (around the 1Gb throughput range) to compete around the SRX340, PA-3020, Fortinet 500D etc. arena.

Wouldn't the low end be covered by the ASAs with FirePOWER? To me these just extend the product line above the 5585-X.

-Otanx

Dieselboy


dlots

I would advise against buying version 1 of any Cisco hardware system.

Otanx

Quote from: dlots on February 29, 2016, 10:29:02 AM
I would advise against buying version 1 of any Cisco hardware system.

Fixed that for you  :)

-Otanx