{"product_id":"cisco-secure-firewall-1250-license-options","title":"Cisco Secure Firewall 1250 - License Options","description":"\u003cp class=\"title topictitle2\"\u003e\u003cspan style=\"color: rgb(0, 0, 0);\"\u003eCisco FTD licensing uses Smart Licensing with a base licence plus add-ons: Threat (IPS), Malware (AMP), and URL Filtering, all managed via Cisco Smart Software Manager.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"title topictitle2\"\u003e\u003cspan style=\"color: rgb(191, 0, 29);\"\u003e\u003cstrong\u003eAbout FTD Licensing\u003cbr\u003e\u003cbr\u003e\u003c\/strong\u003e\u003c\/span\u003e\u003cspan style=\"color: rgb(191, 0, 29);\"\u003e\u003cstrong\u003e\u003c\/strong\u003e\u003c\/span\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eThe Cisco Secure Firewall 1200 Series supports Cisco Secure Firewall Threat Defense (FTD). \u003cbr\u003e\u003cbr\u003eThe base license provides core firewall functionality such as routing, NAT, VPN, and standard security services, while advanced features are enabled through additional subscriptions. These optional licenses include Threat\/IPS protection with Snort 3 and Talos updates, URL filtering, and Malware Defense for advanced file and sandbox analysis.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp data-is-only-node=\"\" data-is-last-node=\"\" data-end=\"787\" data-start=\"470\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eCisco uses Smart Licensing for the 1200 Series, with subscriptions commonly available in 1-, 3-, or 5-year terms. Many deployments use bundled security packages that combine IPS, malware, and URL filtering services, while remote-access VPN connectivity through Cisco Secure Client may require separate user licensing.\u003c\/span\u003e\u003c\/p\u003e\n\u003csection class=\"body conbody\"\u003e\n\u003ctable width=\"100%\"\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd style=\"width: 38.0075%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cstrong\u003e Subscription You Purchase\u003c\/strong\u003e\u003c\/span\u003e\u003c\/td\u003e\n\u003ctd style=\"width: 57.9925%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cstrong\u003eSmart Licenses You Assign in Firepower System\u003c\/strong\u003e\u003c\/span\u003e\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"width: 38.0075%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eT\u003c\/span\u003e\u003c\/td\u003e\n\u003ctd style=\"width: 57.9925%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eThreat\u003c\/span\u003e\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"width: 38.0075%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eTC\u003c\/span\u003e\u003c\/td\u003e\n\u003ctd style=\"width: 57.9925%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eThreat + URL Filtering\u003c\/span\u003e\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"width: 38.0075%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eTM\u003c\/span\u003e\u003c\/td\u003e\n\u003ctd style=\"width: 57.9925%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eThreat + Malware\u003c\/span\u003e\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"width: 38.0075%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eTMC\u003c\/span\u003e\u003c\/td\u003e\n\u003ctd style=\"width: 57.9925%;\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eThreat + Malware + URL Filtering\u003c\/span\u003e\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003c\/tbody\u003e\n\u003c\/table\u003e\n\u003cp id=\"ariaid-title15\" class=\"title topictitle4\"\u003e\u003cstrong\u003e\u003cspan style=\"color: rgb(191, 0, 29);\"\u003e\u003cbr\u003eThreat Licenses\u003c\/span\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003csection class=\"body refbody\"\u003e\n\u003csection id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__section_3C0ACEA2F219407BB764D9F53DF19621\" class=\"section\"\u003e\n\u003cp id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-000000f8\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eA Threat license allows you to perform intrusion detection and prevention, file control, and Security Intelligence filtering:\u003c\/span\u003e\u003c\/p\u003e\n\u003cul class=\"ul\"\u003e\n\u003cli id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__li_E7FF3C179336445FA5D4D8F52FE52304\" class=\"li\" style=\"color: rgb(64, 64, 64);\"\u003e\n\u003cp id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-000000fa\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cem id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-000000fc\" class=\"ph i\"\u003eIntrusion detection and prevention\u003c\/em\u003e allows you to analyze network traffic for intrusions and exploits and, optionally, drop offending packets.\u003c\/span\u003e\u003c\/p\u003e\n\u003c\/li\u003e\n\u003cli id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__li_DB7D24190B3F45B89A1D221FBD79DC3B\" class=\"li\" style=\"color: rgb(64, 64, 64);\"\u003e\n\u003cp id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-000000fd\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cem id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-000000ff\" class=\"ph i\"\u003eFile control\u003c\/em\u003e allows you to detect and, optionally, block users from uploading (sending) or downloading (receiving) files of specific types over specific application protocols. \u003cem id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-00000100\" class=\"ph i\"\u003e\u003cspan class=\"ph\"\u003eAMP for Networks\u003c\/span\u003e\u003c\/em\u003e, which requires a Malware license, allows you to inspect and block a restricted set of those file types based on their dispositions.\u003c\/span\u003e\u003c\/p\u003e\n\u003c\/li\u003e\n\u003cli id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__li_A4BFF1E86902453EB201CB1E653B8DCD\" class=\"li\" style=\"color: rgb(64, 64, 64);\"\u003e\n\u003cp id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-00000103\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cem id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-00000105\" class=\"ph i\"\u003eSecurity Intelligence filtering\u003c\/em\u003e allows you to block —deny traffic to and from—specific IP addresses, URLs, and DNS domain names, before the traffic is subjected to analysis by access control rules. Dynamic feeds allow you to immediately block connections based on the latest intelligence. Optionally, you can use a “monitor-only” setting for Security Intelligence filtering.\u003c\/span\u003e\u003c\/p\u003e\n\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eYou can purchase a Threat license as a stand-alone subscription (T) or in combination with URL Filtering (TC), Malware (TM), or both (TMC).\u003c\/span\u003e\u003c\/p\u003e\n\u003cp id=\"reference_C38742BBC6364CA7BA6F6DA4E3A8C6F7__ID-2240-0000010a\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eIf you disable Threat on managed devices, the \u003cspan class=\"ph\"\u003eFirepower Management Center\u003c\/span\u003e stops acknowledging intrusion and file events from the affected devices. As a consequence, correlation rules that use those events as a trigger criteria stop firing. Additionally, the \u003cspan class=\"ph\"\u003eFirepower Management Center\u003c\/span\u003e will not contact the internet for either Cisco-provided or third-party Security Intelligence information. You cannot re-deploy existing intrusion policies until you re-enable Threat.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp id=\"ariaid-title14\" class=\"title topictitle4\"\u003e\u003cstrong\u003e\u003cspan style=\"color: rgb(191, 0, 29);\"\u003eMalware Licenses for \u003cspan class=\"ph\"\u003eFirepower Threat Defense\u003c\/span\u003e Devices\u003c\/span\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003csection class=\"body refbody\"\u003e\n\u003csection id=\"reference_A9ED087DCFE949168C403EA2EA140063__section_DFDE67C704604FE49A1BF0D7C46753CF\" class=\"section\"\u003e\n\u003cp id=\"reference_A9ED087DCFE949168C403EA2EA140063__ID-2240-0000017e\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eA Malware license for \u003cspan class=\"ph\"\u003eFirepower Threat Defense\u003c\/span\u003e devices allows you to perform Cisco Advanced Malware Protection (AMP) with \u003cspan class=\"ph\"\u003eAMP for Networks\u003c\/span\u003e and \u003cspan class=\"ph\"\u003eCisco Threat Grid\u003c\/span\u003e. With this feature, you can use \u003cspan class=\"ph\"\u003eFirepower Threat Defense\u003c\/span\u003e devices to detect and block malware in files transmitted over your network. To support this feature license, you can purchase the Malware (AMP) service subscription as a stand-alone subscription or in combination with Threat (TM) or Threat and URL Filtering (TMC) subscriptions.\u003c\/span\u003e\u003c\/p\u003e\n\u003cdiv style=\"text-align: start;\" class=\"tableContainer\"\u003e\n\u003ctable role=\"note\" border=\"0\" class=\"olh_note\"\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd border=\"0\" role=\"heading\" class=\"olh_note\" width=\"1%\"\u003e\n\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e \u003cimg style=\"margin-bottom: 16px; float: none;\" alt=\"Pencil icon\" src=\"https:\/\/www.cisco.com\/content\/dam\/en\/us\/td\/i\/templates\/note.gif\"\u003e \u003c\/span\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cb\u003eNote\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003c\/td\u003e\n\u003ctd class=\"olh_note\" border=\"0\"\u003e\n\u003csection class=\"note__content\"\u003e\u003chr\u003e\n\u003cp id=\"reference_A9ED087DCFE949168C403EA2EA140063__ID-2240-00000185\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cspan class=\"ph\"\u003eFirepower Threat Defense\u003c\/span\u003e managed devices with Malware licenses enabled periodically attempt to connect to the AMP cloud even if you have not configured dynamic analysis. Because of this, the device’s Interface Traffic dashboard widget shows transmitted traffic; this is expected behavior.\u003c\/span\u003e\u003c\/p\u003e\n\u003chr\u003e\u003c\/section\u003e\n\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003c\/tbody\u003e\n\u003c\/table\u003e\n\u003c\/div\u003e\n\u003cp id=\"reference_A9ED087DCFE949168C403EA2EA140063__ID-2240-0000018a\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eYou configure \u003cspan class=\"ph\"\u003eAMP for Networks\u003c\/span\u003e as part of a file policy, which you then associate with one or more access control rules. File policies can detect your users uploading or downloading files of specific types over specific application protocols. \u003cspan class=\"ph\"\u003eAMP for Networks\u003c\/span\u003e allows you to use local malware analysis and file preclassification to inspect a restricted set of those file types for malware. You can also download and submit specific file types to the \u003cspan class=\"ph\"\u003eCisco Threat Grid\u003c\/span\u003e cloud for dynamic and Spero analysis to determine whether they contain malware. For these files, you can view the network file trajectory, which details the path the file has taken through your network. The Malware license also allows you to add specific files to a file list and enable the file list within a file policy, allowing those files to be automatically allowed or blocked on detection.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp id=\"reference_A9ED087DCFE949168C403EA2EA140063__ID-2240-00000196\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eIf you disable all your Malware licenses, the system stops querying the AMP cloud, and also stops acknowledging retrospective events sent from the AMP cloud. You cannot re-deploy existing access control policies if they include \u003cspan class=\"ph\"\u003eAMP for Networks\u003c\/span\u003e configurations. Note that for a very brief time after a Malware license is disabled, the system can use existing cached file dispositions. After the time window expires, the system assigns a disposition of \u003ccode id=\"reference_A9ED087DCFE949168C403EA2EA140063__ID-2240-0000019c\" class=\"ph codeph\"\u003eUnavailable\u003c\/code\u003e to those files.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp id=\"reference_A9ED087DCFE949168C403EA2EA140063__ID-2240-0000019d\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eNote that a Malware license is required only if you deploy \u003cspan class=\"ph\"\u003eAMP for Networks\u003c\/span\u003e and \u003cspan class=\"ph\"\u003eCisco Threat Grid\u003c\/span\u003e. Without a Malware license, the \u003cspan class=\"ph\"\u003eFirepower Management Center\u003c\/span\u003e can receive AMP for Endpoints malware events and indications of compromise (IOC) from the AMP cloud.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eSee also important information at \u003ca href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/firepower\/601\/configuration\/guide\/fpmc-config-guide-v601\/Reference_a_wrapper_Chapter_topic_here.html#id_101648\" class=\"xref\" style=\"color: rgb(64, 64, 64);\"\u003eLicense Requirements for File and Malware Policies\u003c\/a\u003e.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp id=\"ariaid-title16\" class=\"title topictitle4\"\u003e\u003cstrong\u003e\u003cspan style=\"color: rgb(191, 0, 29);\"\u003eURL Filtering Licenses for \u003cspan class=\"ph\"\u003eFirepower Threat Defense\u003c\/span\u003e Devices\u003c\/span\u003e\u003c\/strong\u003e\u003c\/p\u003e\n\u003csection class=\"body refbody\"\u003e\n\u003csection id=\"reference_0FB126619D0649D79B4F666AACE82BAD__section_94660A4F86DF429297F4AE620ACFBDCF\" class=\"section\"\u003e\n\u003cp id=\"reference_0FB126619D0649D79B4F666AACE82BAD__ID-2240-0000015a\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eThe URL Filtering license allows you to write access control rules that determine the traffic that can traverse your network based on URLs requested by monitored hosts, correlated with information about those URLs. To support this feature license, you can purchase the URL Filtering (URL) service subscription as a stand-alone subscription or in combination with Threat (TC) or Threat and Malware (TMC) subscriptions.\u003c\/span\u003e\u003c\/p\u003e\n\u003cdiv style=\"text-align: start;\" class=\"tableContainer\"\u003e\n\u003ctable role=\"note\" border=\"0\" class=\"olh_note\"\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd border=\"0\" role=\"heading\" class=\"olh_note\" width=\"1%\"\u003e\n\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e \u003cimg style=\"margin-bottom: 16px; float: none;\" alt=\"Magnifying glass\" src=\"https:\/\/www.cisco.com\/content\/dam\/en\/us\/td\/i\/templates\/tip.gif\"\u003e \u003c\/span\u003e\n\u003cp\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003e\u003cb\u003eTip\u003c\/b\u003e\u003c\/span\u003e\u003c\/p\u003e\n\u003c\/td\u003e\n\u003ctd class=\"olh_note\" border=\"0\"\u003e\n\u003csection class=\"note__content\"\u003e\u003chr\u003e\n\u003cp id=\"reference_0FB126619D0649D79B4F666AACE82BAD__ID-2240-0000015d\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eWithout a URL Filtering license, you can specify individual URLs or groups of URLs to allow or block. This gives you granular, custom control over web traffic, but does not allow you to use URL category and reputation data to filter network traffic.\u003c\/span\u003e\u003c\/p\u003e\n\u003chr\u003e\u003c\/section\u003e\n\u003c\/td\u003e\n\u003c\/tr\u003e\n\u003c\/tbody\u003e\n\u003c\/table\u003e\n\u003c\/div\u003e\n\u003cp id=\"reference_0FB126619D0649D79B4F666AACE82BAD__ID-2240-00000160\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eAlthough you can add category and reputation-based URL conditions to access control rules without a URL Filtering license, the \u003cspan class=\"ph\"\u003eFirepower Management Center\u003c\/span\u003e will not download URL information. You cannot deploy the access control policy until you first add a URL Filtering license to the \u003cspan class=\"ph\"\u003eFirepower Management Center\u003c\/span\u003e, then enable it on the devices targeted by the policy.\u003c\/span\u003e\u003c\/p\u003e\n\u003cp id=\"reference_0FB126619D0649D79B4F666AACE82BAD__ID-2240-00000166\" class=\"p\"\u003e\u003cspan style=\"color: rgb(64, 64, 64);\"\u003eIf you disable the URL Filtering license on managed devices, you may lose access to URL filtering. If your license expires or if you disable it, access control rules with URL conditions immediately stop filtering URLs, and your \u003cspan class=\"ph\"\u003eFirepower Management Center\u003c\/span\u003e can no longer download updates to URL data. You cannot re-deploy existing access control policies if they include rules with category and reputation-based URL conditions.\u003c\/span\u003e\u003c\/p\u003e\n\u003c\/section\u003e\n\u003c\/section\u003e\n\u003c\/section\u003e\n\u003c\/section\u003e\n\u003c\/section\u003e\n\u003c\/section\u003e\n\u003c\/section\u003e","brand":"Network Warehouse V6","offers":[{"title":"Threat \/ 1 Year","offer_id":56800329204092,"sku":"L-CSF1250-T-1Y","price":2998.62,"currency_code":"GBP","in_stock":true},{"title":"Threat \/ 3 Year","offer_id":56800329236860,"sku":"L-CSF1250-T-3Y","price":8995.91,"currency_code":"GBP","in_stock":true},{"title":"Threat \/ 5 Year","offer_id":56800329269628,"sku":"L-CSF1250-T-5Y","price":14993.16,"currency_code":"GBP","in_stock":true},{"title":"Threat + URL \/ 1 Year","offer_id":56800329302396,"sku":"L-CSF1250-TC-1Y","price":5997.26,"currency_code":"GBP","in_stock":true},{"title":"Threat + URL \/ 3 Year","offer_id":56800329335164,"sku":"L-CSF1250-TC-3Y","price":17991.8,"currency_code":"GBP","in_stock":true},{"title":"Threat + URL \/ 5 Year","offer_id":56800329367932,"sku":"L-CSF1250-TC-5Y","price":29986.33,"currency_code":"GBP","in_stock":true},{"title":"Threat + Malware \/ 1 Year","offer_id":56800329400700,"sku":"L-CSF1250-TM-1Y","price":5997.26,"currency_code":"GBP","in_stock":true},{"title":"Threat + Malware \/ 3 Year","offer_id":56800329433468,"sku":"L-CSF1250-TM-3Y","price":17991.8,"currency_code":"GBP","in_stock":true},{"title":"Threat + Malware \/ 5 Year","offer_id":56800329466236,"sku":"L-CSF1250-TM-5Y","price":29986.33,"currency_code":"GBP","in_stock":true},{"title":"Threat + Malware + URL \/ 1 Year","offer_id":56800329499004,"sku":"L-CSF1250-TMC-1Y","price":8096.31,"currency_code":"GBP","in_stock":true},{"title":"Threat + Malware + URL \/ 3 Year","offer_id":56800329531772,"sku":"L-CSF1250-TMC-3Y","price":24288.93,"currency_code":"GBP","in_stock":true},{"title":"Threat + Malware + URL \/ 5 Year","offer_id":56800329564540,"sku":"L-CSF1250-TMC-5Y","price":40481.54,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0373\/2137\/5882\/files\/1250_License.png?v=1779458998","url":"https:\/\/networkwarehouse.co.uk\/products\/cisco-secure-firewall-1250-license-options","provider":"Network Warehouse","version":"1.0","type":"link"}