Basic Firepower (NGIPSv)
In our topology NGIPSv (Firepower 6.1.0-330) will be inline mode with management interface.
My server has 6 Ethernet cards so i don't have to play with subinterfaces on Vmware. For inline pair interfaces there's two NICs (eth1 and eth2 on NGIPSv), for management interface eth0 on NGIPSv - bridged to w2k8 interface (vlan33).
Below Layer 2 diagram:
For Vmware we use Cisco_Firepower_NGIPSv_VMware-ESXi-6.1.0-330.ovf.
NGIPSv needs license to work (install on FMC) and there's no demo license yet (trial, enabled on firepower or generate on Cisco site). So we need to buy one :( or asked for demo license from your Cisco partner. For lab purpose we need to have license: Protection and Control, URL filtering, Malware.
For Firepower Management Center we can enable 90 days trial.
On NGIPSv:
> show version
-------------------[ firepower ]--------------------
Model : NGIPSv for VMware (69) Version 6.1.0.3 (Build 57)
UUID : c94a1238-285e-33e7-97fe-fc34041aed03
Rules update version : 2017-04-25-003-vrt
VDB version : 270
----------------------------------------------------
> show interfaces
----------------------[ eth0 ]----------------------
Physical Interface : eth0
Type : Management
Status : Enabled
Link Mode : Autoneg
MDI/MDIX : Auto
MTU : 1500
MAC Address : 00:0C:29:E6:D9:63
IPv4 Address : 192.168.0.248
----------------------[ eth1 ]----------------------
Physical Interface : eth1
Type : Inline
Security Zone : Internal
Status : Enabled
Link Mode : Autoneg
MDI/MDIX : Auto
MTU : 1518
MAC Address : 00:0C:29:E6:D9:6D
Load Balancing Mode : N/A
----------------------[ eth2 ]----------------------
Physical Interface : eth2
Type : Inline
Security Zone : External
Status : Enabled
Link Mode : Autoneg
MDI/MDIX : Auto
MTU : 1518
MAC Address : 00:0C:29:E6:D9:77
Load Balancing Mode : N/A
----------------------------------------------------
> configure manager add 192.168.0.247 123456
On FMC:
Devices->Device management->Add->Add Device:
On NGIPSv:
> show managers
Type : Manager
Host : 192.168.0.247
Registration : Completed
Subscribe to:
Posts (Atom)