Firepower Feature Matrix
Firepower Feature Matrix
Firepower Feature Matrix
06 February 2020
© 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Partner Confidential Information.
Contents
Introduction 2
Platform Selection 2
ASA or FTD 2
ASA Management Selection: 3
NGFW Management Selection: 4
NGFW Management Selection - Continued: 5
Management Features Matrix – ASA 6
Management Features Matrix – FTD 15
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 1 of 27
Introduction
The purpose of this document is to inform and accelerate our users decision-making when choosing between Cisco ASA or FTD
platforms and available management options. More information ASA to FMT migration is available here: Cisco ASA to FTD using
FMT
Platform Selection
ASA or FTD
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 2 of 27
ASA Management Selection:
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 3 of 27
NGFW Management Selection:
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 4 of 27
NGFW Management Selection - Continued:
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 5 of 27
Management Features Matrix – ASA
LEGEND
Matured, tested, and verified
Not Supported
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 6 of 27
Cisco Security Manager Adaptive Security Device Cisco Defense Orchestrator
Features
(4.20) Manager (7.13) (Dec 2019)
Firewall Operating Mode Features
Stateful Transparent Firewall ✔ ✔ ✗
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 7 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
Stateful Firewall Object Features
Object based acc. ctrl policy ✔ ✔ ✔
IP address objects (v4 & 6) ✔ ✔ ✔
Object groups ✔ ✔ ✔
Groups of groups ✔ ✔ ✔
UDP and TCP ports in one ✔ ✔ ✔
object
Address ranges 1.1.1.10-20 ✔ ✔ ✔
Port ranges ✗ ✗ ✗
Object change history ✔ ✗ ✔
Find unused objects ✔ ✗ ✔
IP object based on a ✔ ✔ ✔
host/domain name (FQDN
object)
Classic Firewall Features
Access Ctrl rules (IP, port) ✔ ✔ ✔
Integrated routing and Bridging ✔ ✔ ✔
in the same context
TCP State bypass ✔ ✔ ✔
Only packets that belong to ✔ ✔ ✔
established sessions can be
allowed through the firewall
TCP Sequence random. ✔ ✔ ✔
Connection limits and TCP ✔ ✔ ✔
Intercept
Dead Connection Detection ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 8 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
Advanced Protocol Inspection Features
SIP ✔ ✔ ✔
FTP ✔ ✔ ✔
DNS ✔ ✔ ✔
DCE-RPC ✔ ✔ ✔
GTP ✔ ✔ ✔
H323 (H225, RAS) ✔ ✔ ✔
ICMP ✔ ✔ ✔
NetBIOS ✔ ✔ ✔
RTSP ✔ ✔ ✔
SCCP ✔ ✔ ✔
RSH ✔ ✔ ✔
ESMTP ✔ ✔ ✔
SQLNET ✔ ✔ ✔
SUNRPC ✔ ✔ ✔
XDMCP ✔ ✔ ✔
TFTP ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 9 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
VPN -> Site-to-Site Features
IKEv1, IKEv2 ✔ ✔ ✔
Static, Dynamic Peering ✔ ✔ ✔
IPv4, IPv6 Addressing ✔ ✔ ✔
PSK Authentication ✔ ✔ ✔
Certificate Authentication ✔ ✔ ✔
Route Based VPN ✔ ✔ ✔
Firepower VPN (7xxx and 8xxx ✔ ✔ ✔
appliances)
Monitoring ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 10 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
Layer 2 - 7 Access Control Filter Features
IP address ✔ ✔ ✔
VLAN ✔ ✔ ✔
User ID / User Group ✔ ✔ ✔
Ports ✔ ✔ ✔
Protocol ✔ ✔ ✔
Objects ✔ ✔ ✔
SGT ✔ ✔ ✔
Trusting Traffic / No inspection ✔ ✔ ✔
Tunnel Policies ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 11 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
NGFW Layer 4 - 7 Firewall Functionality Features
Application Control ✗ ✗ ✗
Limit bandwidth by ✗ ✗ ✗
user/application (Rate Limiting)
URL Filtering ✗ ✗ ✗
SSL Decryption in software ✗ ✗ ✗
SSL Decryption in hardware ✗ ✗ ✗
OpenAppID ✗ ✗ ✗
AMP For networks ✗ ✗ ✗
ThreatGRID Dynamic Analysis ✗ ✗ ✗
Threat/Risk Reports ✗ ✗ ✗
Web SafeSearch and YouTube ✗ ✗ ✗
Edu
TLS Proxy for Encrypted Voice ✗ ✗ ✗
Inspection
Web Cache Services Using ✔ ✔ ✔
WCCP
Pre-filter Policy (Tunneled & ✔ ✔ ✔
Fastpath)
Firewall management automation
Hit Counts ✔ ✔ ✔
Rule Conflict Detection ✔ ✗ ✔
(Redundant & Shadowed)
Object Conflict detection ✗ ✗ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 12 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
Logging & Analytic Features
Log connections to ✔ ✔ ✔
management console
Send syslogs- from the ✔ ✔ ✔
management console
Send syslogs - directly from the ✔ ✔ ✔
device
Security Analytics and Logging ✗ ✗ ✗
Dashboards ✔ ✔ ✗
Reporting ✔ ✗ ✗
estreamer ✗ ✗ ✗
CEF ✗ ✗ ✗
Netflow ✔ ✔ ✔
Cisco Threat Response (CTR) ✗ ✗ ✗
Integration
Risk Reports/SRA ✗ ✗ ✗
Health Functionality ✔ ✔ ✗
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 13 of 27
Adaptive Security Device Cisco Defense Orchestrator
Features Cisco Security Manager (4.20)
Manager (7.13) (Dec 2019)
APIs
REST API ✔ ✔ ✔
Host Input API ✗ ✗ ✗
Remediation API ✗ ✗ ✗
Database Access API ✗ ✗ ✗
Estreamer API ✗ ✗ ✗
Workflows (Submitter, ✔ ✗ ✔
Approver, Deployer)
Ticket Management System ✔ ✗ ✔
Integration
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 14 of 27
Management Features Matrix – FTD
LEGEND
Matured, tested, and verified
Not Supported
Management Authentication Local, AD, Radius Local Admin and RADIUS SAML 2FA -- Cisco provided
(Cisco Secure Sign-On) or Roll
Your Own
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 15 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Management RBAC Granular RBAC provided locally Available w/ RADIUS Three roles: Super Admin, Admin
(Authorization) authentication and Read-Only
Roles: RO, RW and Admin
Management Audit (Accounting) Audit Logs. report can be ✔ Yes. ChangeLog for all
generated from these logs in Configuration Changes. Data is
HTML, PDF and CSV formats stored and accessible for at least
one year
Deployment History ✔ ✔ ✔
- High level indication in Deploy
Policies window
Pending Changes ✔ ✔
- Interface and ACP changes in
Audit Log
- Available for DNS, File, Health,
Identity, Intrusion, Network
Policy Compare Analysis, SSL policies ✔ ✔
- Interface and ACP changes in
Audit Log
Configuration Archive ✔ ✔ ✗
Firewall Operating Mode Features
Stateful Transparent firewall ✔ ✗ ✗
Stateful Routed firewall ✔ ✔ ✔
Multi-Instance ✔ ✗ ✗
Scalability and High Availability Features
Active/Active Failover ✔ ✗ ✗
Active/Standby Failover ✔ ✔ ✔
Clustering on 5500-X ✔ ✗ ✗
Intra-Chassis Clustering on ✔ ✗ ✗
Firepower Appliance
Inter-Chassis Clustering on ✔ ✗ ✗
Firepower Appliance
Stacking ✔ ✗ ✗
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 16 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Hardware Specific Features
Flow Offload on 9300 and 4100 ✔ ✔ ✔
Fail to wire interfaces ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 17 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Stateful Firewall Object Features
Object groups ✔ ✔ ✔
Groups of groups ✔ ✔ ✔
Port ranges ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 18 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Stateful Firewall Predefined Object Features
IPv4 Private-Use - All RFC1918 ✔ ✔ ✔
IPv4 Private-Use - 10/8 ✔ ✔ ✔
IPv6 Link-Local ✔ ✔ ✔
IPv4 Multicast ✔ ✔ ✔
any ipv4 ✔ ✔ ✔
any ipv6 ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 19 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Classic Firewall Features
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 20 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Advanced Protocol Inspection Features
SIP ✔ ✔ ✔
FTP ✔ ✔ ✔
DNS ✔ ✔ ✔
DCE-RPC ✔ ✔ ✔
GTP ✔ ✔ ✔
H323 (H225, RAS) ✔ ✔ ✔
ICMP ✔ ✔ ✔
NetBIOS ✔ ✔ ✔
RTSP ✔ ✔ ✔
SCCP ✔ ✔ ✔
RSH ✔ ✔ ✔
ESMTP ✔ ✔ ✔
SQLNET ✔ ✔ ✔
SUNRPC ✔ ✔ ✔
XDMCP ✔ ✔ ✔
TFTP ✔ ✔ ✔
Stateful Firewall Other Features
NAT Firepower NAT also included ✔ GUI also includes a NAT Wizard
for some use cases
Routing OSPF, BGP, RIP, Multicast, Static and Route Tracking(SLA) Static via UI; Other protocols via
Static, Route Tracking(SLA) - on UI FDM UI
Supported on UI OSPF, BGP and respective route
EIGRP, PBR, ISIS, BFD, ECMP - object - SmartCLI
Flexconfig Other Dynamic Routing protocols
Only API for static route + PBR - FlexConfig
APIs available for Static Route,
OSPF, BGP and generic
Flexconfig
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 21 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
VPN -> Site-to-Site Features
IKEv1, IKEv2 ✔ ✔ ✔
Static, Dynamic Peering ✔ ✔ ✔
IPv4, IPv6 Addressing ✔ ✔ ✔
PSK Authentication ✔ ✔ ✔
Certificate Authentication ✔ ✔ ✗
Route Based VPN ✗ ✗ ✗
Firepower VPN (7xxx and 8xxx ✔ ✗ ✗
appliances)
Monitoring ✔ ✗ ✔
Authentication Protocol RADIUS, LDAP RADIUS, LDAP, Local RADIUS, LDAP, Local
Certificate Authentication ✔ ✔ ✔
2FA/MFA ✔ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 22 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
NGFW Layer 2 - 7 Access Control Filter Features
Zone (a logical group of physical ✔ ✔ ✔
or virtual interfaces)
IP address ✔ ✔ ✔
Geolocation ✔ ✔ ✔
VLAN ✔ ✔ ✔
User ID / User Group ✔ ✔ ✔
VDI user identity ✔ ✗ ✗
AppID ✔ ✔ ✔
Ports ✔ ✔ ✔
Protocol ✔ ✔ ✔
URL ✔ ✔ ✔
Objects ✔ ✔ ✔
SGT ✔ ✔ ✗
Device type (ISE) ✔ ✔ ✗
Location IP (ISE) ✔ ✔ ✗
Trusting Traffic / No inspection ✔ ✔ ✔
Tunnel Policies ✗ ✗ ✗
X-Forwarded-For policy ✔ ✗ ✗
NGFW Traffic Awareness & Network Discovery Features
Network Discovery ✔ ✗ ✗
Application Discovery ✔ ✗ ✗
User Discovery ✔ ✗ ✗
Indicators Of Compromise, ✔ ✗ ✗
Impact Analysis, Firepower
recommendation, etc.
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 23 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
NGFW Identity Awareness & Control Features
Passive authentication ✔ ✔ ✔
Active Authentication/Captive ✔ ✔ ✔
Portal/Cut Through Proxy and
Direct Authentication
Enforce traffic policy by SGT ✔ ✔ ✗
Read SGT from packets ✔ ✔ ✗
Rapid Threat Containment using ✔ ✗ ✗
ISE
NGFW Threat Prevention (IPS & Malware) Features
Snort - best in class IPS ✔ ✔ ✔
Normalization and inspection of ✔ ✔ ✔
traffic up to application layer for
anti-evasion
Custom IPS Rules ✔ ✗ ✗
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 24 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
NGFW Layer 4 - 7 Firewall Functionality Features
Application Control ✔ ✔ ✔
Limit bandwidth by ✔ Flexconfig ✗
user/application (Rate Limiting)
URL Filtering ✔ ✔ ✔
SSL Decryption in software ✔ ✔ ✔
SSL Decryption in hardware ✔ ✔ ✔
OpenAppID ✔ ✔ ✔
AMP For networks ✔ ✔ ✔
ThreatGRID Dynamic Analysis ✔ ✗ ✗
Threat/Risk Reports ✔ ✗ ✗
Web SafeSearch and YouTube ✔ ✔ ✔
Edu
TLS Proxy for Encrypted Voice ✗ ✗ ✗
Inspection
Web Cache Services Using WCCP Flexconfig Flexconfig ✗
Pre-filter Policy (Tunneled & ✔ ✗ ✗
Fastpath)
Firewall management automation
Hit Counts ✔ ✔ ✗
Rule Conflict Detection ✔ ✗ ✗
(Redundant & Shadowed)
Object Conflict detection ✗ ✔ ✔
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 25 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
Logging & Analytic Features
Log connections to management ✔ ✔ ✔
console
Send syslogs- from the ✔ ✔ ✗
management console
Send syslogs - directly from the ✔ ✔ ✔
device
Security Analytics and Logging ✗ ✗ ✔
Dashboards ✔ ✔ Dashboards available for:
- Predefined and Customizable - Multiple predefined dashboards Top Applications
dashboard and widgets for for health, network and threat Top Attackers
network and threat Top Destinations
- Limited Device health Top Targets
Top Threats
Reporting ✔ including ✗ ✗
- Provides templates for reports.
- Reports can be exported etc.
- Report Designer can convert
Dashboard to Reports
estreamer ✔ ✗ ✗
CEF ✗ ✗ ✗
Netflow Flexconfig Flexconfig Flexconfig
Cisco Threat Response (CTR) ✔ ✔ ✔
Integration
Risk Reports/SRA ✔ ✗ ✗
Health Functionality ✔ ✔ ✗
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 26 of 27
Firepower Management Center Firepower Device Manager Cisco Defense Orchestrator
Features
(6.5) (6.5) (Dec 2019)
APIs
REST API ✔ - Limited FTD APIs available for all FDM FTD APIs available in co-
existance with CDO
Host Input API ✔ ✗ ✗
Remediation API ✔ ✗ ✗
Database Access API ✔ ✗ ✗
Estreamer API ✔ ✗ ✗
Workflows (Submitter, Approver, ✗ ✗ ✗
Deployer)
Ticket Management System ✗ ✗ Via Rest API
Integration
Divya & Alan v.6.5 © 2020 Cisco and/or its affiliates. All rights reserved. This document is Cisco Confidential Information. Page 27 of 27