FirePOWER moge konfigurowac przez konsole (session sfr console) oraz ASDM z zakladek FirePOWER (dziala na Windows 7 Prof. x64, na Debian 8.1 Jessie z IceadTea [JRE version 1.7.0_79 OpenJDK 64-Bit Server VM] nie widze okien FirePOWER w ASDMie).
W consoli mam komendy do zmiany interfesju i portu zarzadzania tym modulem. Gdy zmieniam port management na np. LAN (gi1/1), dodaje adresacje, ustawiam 2 opcje enable-management-channel oraz enable-event-channel, na porcie Gi1/1 (LAN) nie moge zarzadzac tym modulem a sh module sfr details pokazuje mi:
Kod: Zaznacz cały
ASA5506-TEST# sh module sfr details
Getting details from the Service Module, please wait...
Card Type: FirePOWER Services Software Module
Model: ASA5506
Hardware version: N/A
Serial Number: JAD190503N7
Firmware version: N/A
Software version: 5.4.1-211
MAC Address Range: 84b8.0276.9197 to 84b8.0276.9197
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc: Normal Operation
App. version: 5.4.1-211
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr: No DC Configured
Mgmt IP addr: 0.0.0.0
Mgmt Network mask: 0.0.0.0
Mgmt Gateway: 0.0.0.0
Mgmt web ports: 443
Mgmt TLS enabled: true
Kod: Zaznacz cały
Configure> show network
===============[ System Information ]===============
Hostname : SFR-TEST
Domains : example.net
Management port : 8305
======================[ eth0 ]======================
State : Disabled
Channels : Management & Events
Mode :
MDI/MDIX : Auto/MDIX
MTU : 1500
MAC Address : 84:B8:02:76:91:97
----------------------[ IPv4 ]----------------------
Configuration : Disabled
----------------------[ IPv6 ]----------------------
Configuration : Disabled
===============[ Proxy Information ]================
State : Disabled
Authentication : Disabled
Gdy powroce do interfejsu Management1/1 (FirePoWER pokazuje mi go jako eth0), sh module sfr details daje mi:
Kod: Zaznacz cały
ASA5506-TEST# sh module sfr details
Getting details from the Service Module, please wait...
Card Type: FirePOWER Services Software Module
Model: ASA5506
Hardware version: N/A
Serial Number: JAD190503N7
Firmware version: N/A
Software version: 5.4.1-211
MAC Address Range: 84b8.0276.9197 to 84b8.0276.9197
App. name: ASA FirePOWER
App. Status: Up
App. Status Desc: Normal Operation
App. version: 5.4.1-211
Data Plane Status: Up
Console session: Ready
Status: Up
DC addr: No DC Configured
Mgmt IP addr: 172.31.255.2
Mgmt Network mask: 255.255.255.240
Mgmt Gateway: 172.31.255.1
Mgmt web ports: 443
Mgmt TLS enabled: true
Kod: Zaznacz cały
Configure> show network
===============[ System Information ]===============
Hostname : SFR-TEST
Domains : example.net
Management port : 8305
IPv4 Default route
Gateway : 172.31.255.1
======================[ eth0 ]======================
State : Enabled
Channels : Management & Events
Mode :
MDI/MDIX : Auto/MDIX
MTU : 1500
MAC Address : 84:B8:02:76:91:97
----------------------[ IPv4 ]----------------------
Configuration : Manual
Address : 172.31.255.2
Netmask : 255.255.255.240
Broadcast : 172.31.255.15
----------------------[ IPv6 ]----------------------
Configuration : Disabled
===============[ Proxy Information ]================
State : Disabled
Authentication : Disabled
Moje pytania brzmia:
1) w jaki sposob moge zmienic interfejs do zarzadzania modulem SFR?
2) Gdzie znajde jakis CLI Guide?