<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower deployments really slow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/4007037#M1005758</link>
    <description>&lt;P&gt;I've performed many tests on ASA's repurposed as FTD, and new FirePower devices. I wholeheartedly agree, the deployment process of FTD through FDM (or even FMCv) is embarrassingly slow (and way more painful to wait for failure, if you know the deployment will fail--like 15 minutes on a 1010!). It's worse than using Ansible on a network. I realize FTD is really CiscoLinux, and I feel very poorly engineered using open-source code, such as Charon (VPN), which is painful to work with on its own. But in my honest opinion, I'd much rather continue struggling with old Java code using ASDM on an ASA than continue working with the slowest GUI-based deployments in the industry. I'm sorry, but FDM/FMC have some serious maturing needs.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jan 2020 15:45:03 GMT</pubDate>
    <dc:creator>bmurphree@myemma.com</dc:creator>
    <dc:date>2020-01-06T15:45:03Z</dc:date>
    <item>
      <title>Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094067#M1005719</link>
      <description>&lt;P&gt;I have new pair of NGFW 2110's. &amp;nbsp;I have a virtual FPMC. &amp;nbsp;This is a new build with relatively few rules (10) and NAT statements (14). &amp;nbsp;If I make a simple change to the policy and deploy it, it seems to take a really long time. &amp;nbsp;I'm regularly seeing 7+ minutes. &amp;nbsp;Is this normal? &amp;nbsp;Why? &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094067#M1005719</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2019-03-12T13:29:15Z</dc:date>
    </item>
    <item>
      <title>I'd expect under a minute</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094068#M1005720</link>
      <description>&lt;P&gt;I'd expect under a minute unless:&lt;/P&gt;
&lt;P&gt;a. A congested WAN is between your FMC and the sensors or&lt;/P&gt;
&lt;P&gt;b. The FMC is on underpowered compute resources (check the FMC status page for details).&lt;/P&gt;
&lt;P&gt;I'd recommend opening a TAC case to have them drill into the root cause if neither of the above is the case.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094068#M1005720</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-15T02:31:22Z</dc:date>
    </item>
    <item>
      <title>FMC and Management port of</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094069#M1005721</link>
      <description>&lt;P&gt;FMC and Management port of both firewalls is on the same LAN. &amp;nbsp;FMC is virtual on a UCS that is currently way under utilized. &amp;nbsp;I'm seeing that the only statistic that is high on the FMC statistics page is that Memory is at 80%. &amp;nbsp;Can I simply add more memory since it was an OVF deployment?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094069#M1005721</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2017-08-15T02:46:17Z</dc:date>
    </item>
    <item>
      <title>You can shutdown the server,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094070#M1005722</link>
      <description>&lt;P&gt;You can shutdown the server, add memory to the VM and restart but I was thinking more about CPU and storage IOPS. If it has the recommended 8 GB you may get some incremental improvement by going up to 12 or 16 GB but a deployment would not normally be a memory-intensive process.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094070#M1005722</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-15T02:50:39Z</dc:date>
    </item>
    <item>
      <title>I agree.  But CPU is fine and</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094071#M1005723</link>
      <description>&lt;P&gt;I agree. &amp;nbsp;But CPU is fine and storage has a long way to go before I am pushing IOPS. &amp;nbsp;It's a Nimble / Cisco Smartstack.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094071#M1005723</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2017-08-15T02:52:38Z</dc:date>
    </item>
    <item>
      <title>Are you running 6.2.1 with</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094072#M1005724</link>
      <description>&lt;P&gt;Are you running 6.2.1 with the 2110s?&lt;/P&gt;
&lt;P&gt;I haven't done any production deployments of those and there may be a not yet publicly-documented bug. I know 6.2.2. is about to be released - I'd reach out to the TAC to see if they can shed some light.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094072#M1005724</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-15T02:56:53Z</dc:date>
    </item>
    <item>
      <title>Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094073#M1005725</link>
      <description>&lt;P&gt;Yes, 6.2.1. &amp;nbsp;I will open a case.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 03:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094073#M1005725</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2017-08-15T03:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198774#M1005726</link>
      <description>&lt;P&gt;what did you find out ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am seeing the same thing on a pair of 2120 with a vFMC running 6.2.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when navigating in the FMC it is very slow especially when you go want to use Connection/events. deployents takes 5-10min&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 17:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198774#M1005726</guid>
      <dc:creator>danhed7400</dc:creator>
      <dc:date>2017-10-14T17:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198870#M1005727</link>
      <description>&lt;P&gt;Just did my first production 2110s last week. In this case we ran 6.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found deployments to take about 1 minute. I recommend upgrading to 6.2.2. to see if that helps. Even if it doesn't, there are many bug fixes there for other things.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 02:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198870#M1005727</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-15T02:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3201102#M1005728</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have installed a pair of 2110 (in HA) and running FMC 6.2.2 code.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The FMC is&amp;nbsp;taking about 8 to 11 minutes each deploy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the FMC health and everything is ok.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="listview_full"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH nowrap="nowrap"&gt;CPU Usage - User&lt;/TH&gt;
&lt;TD&gt;0.10%&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TH nowrap="nowrap"&gt;CPU Usage - System&lt;/TH&gt;
&lt;TD&gt;0.07%&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***&amp;nbsp;This environment isn't in production, no data passing through&amp;nbsp;interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 18:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3201102#M1005728</guid>
      <dc:creator>Rodrigo Rosa da Silva</dc:creator>
      <dc:date>2017-10-18T18:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3202086#M1005729</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May i know if you are using the hard appliance or virtual FMC?&lt;/P&gt;
&lt;P&gt;Because i tried upgrading my FMCv to 6.2.2 but still experience slow deployment timing on FTD 5506X&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Standalone deployment takes around 4mins and HA deployments takes around 8 mins.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 00:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3202086#M1005729</guid>
      <dc:creator>WC615</dc:creator>
      <dc:date>2017-10-20T00:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3308339#M1005730</link>
      <description>&lt;P&gt;Firepower 2110 HA, 6.2.2.1 code&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also taking 7+ minutes for each deployment. Somewhat frustrating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any progress on this?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 15:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3308339#M1005730</guid>
      <dc:creator>dspender</dc:creator>
      <dc:date>2018-01-09T15:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309177#M1005731</link>
      <description>&lt;P&gt;For anyone searching on this. Here is the result of my TAC Case - I have TWO Firepower 2110 devices in HA running on most recent code:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I reviewed the troubleshoot file and I was not able to find any issue.&lt;/P&gt;
&lt;P&gt;As I explained in my previous email this time depends on the bandwidth and the Policy (rules, sensors and so on). I do not consider this time - 7 minutes for deploy as a problem.&lt;/P&gt;
&lt;P&gt;Please let me know if you have any other concerns or questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Business day hours:&amp;nbsp; Mon - Fri - 8AM - 5PM (EST)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;XXXXXXXXXXX&lt;/P&gt;
&lt;P&gt;Cisco Firewall TAC engineer&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 18:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309177#M1005731</guid>
      <dc:creator>dspender</dc:creator>
      <dc:date>2018-01-10T18:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309205#M1005732</link>
      <description>&lt;P&gt;I haven't deployed to 2110's but I agree that 7 minutes is excessive. I'd push back on the TAC and request escalation to get another pair of eyes on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now I am working with a couple of vFTD instances and an FMC VM (all on the same ESXi host which is running exclusively SSD storage) and deployments complete in about 1-1/2 minutes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You had indicated this is a new deployment with minimal policies. Are they in production at this point? I ask because I'm wondering if them being in an HA pair is affecting the time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any possibility of network issues between your FMC and the appliances? You might grab a tcpdump or spanned capture during deployment and see if Wireshark shows any tcp retransmissions or such.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 18:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309205#M1005732</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-01-10T18:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314615#M1005733</link>
      <description>&lt;P&gt;We run a few FTD devices, along with several ASA w/FirePower services and a vFMC.&amp;nbsp; I've found that the deployment times are very sporadic for FTD devices.&amp;nbsp; The two devices that have the longest deployment times are our 2110's running in Active/Failover.&amp;nbsp; Depending on the changes being made, they can take about up to 10 minutes.&amp;nbsp; I've found that 5 minutes is the average, especially for changes to NAT and Access Policy whereas VPN changes seem to push in just a few minutes.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've had several long talks and multiple tickets open for issues/questions with FTD, but I'm at the point where I'm just attributing this to platform maturity.&amp;nbsp; I'm at peace with the length of deployment due to the security the system provides us.&amp;nbsp; We used CSM to manage our ASA firewalls for a long time, so longer deployments I'm used to.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 16:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314615#M1005733</guid>
      <dc:creator>workforcesoftware</dc:creator>
      <dc:date>2018-01-19T16:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314648#M1005734</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm working with many different deployments and I would say 8 minutes with FMCv and HA pair 2110 is normal.&lt;/P&gt;
&lt;P&gt;There is a big difference on a empty box, stand alone or ha pair. ranging from 2 minutes to 10 minutes.&lt;/P&gt;
&lt;P&gt;I believe Cisco will be doing something about this in coming releases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;br, Micke&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 17:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314648#M1005734</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2018-01-19T17:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3315681#M1005735</link>
      <description>&lt;P&gt;It's the same for me on a physical FPMC 1000 with around 15 rules and some very basic NAT &amp;amp; HA configuration, for a single FPR2110 pair - somewhere between 5-7 minutes per deploy even with a single change. I wouldn't say this is a FMCv-specific issue at all and from the horses mouth I was told this was "normal".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's frustrating because under some circumstances&amp;nbsp;traffic may be dropped during a deploy (&lt;STRIKE&gt;the circumstances where this can happen are vague and the documentation has conflicting information with the on-box help, which has information that conflicts with other on-box help&lt;/STRIKE&gt; I just double-checked and it looks like the documentation has been updated to be clearer). We're scheduling any policy change for after-hours as a result, even if it's a single access policy item addition or removal.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 08:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3315681#M1005735</guid>
      <dc:creator>adammckay1</dc:creator>
      <dc:date>2018-01-22T08:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3316841#M1005736</link>
      <description>Yeah, I've also heard this is normal from several resources within Cisco.  The issue of traffic dropping on deployment is the biggest issue I have with the new system.  Gone are the days of making changes during production hours, with little to no impact on the end-user.  That was the one thing I loved the most about the ASAs, especially at our headquarters.</description>
      <pubDate>Tue, 23 Jan 2018 14:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3316841#M1005736</guid>
      <dc:creator>workforcesoftware</dc:creator>
      <dc:date>2018-01-23T14:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3397641#M1005737</link>
      <description>&lt;P&gt;I'm new into the ASA firepower stuff and I think the deployment times are really slow up to 5 minutes. I'm getting gray hair before they're done. And if I deploy a change on a live environment and figure out the rule breaks connectivity for my users it takes at least 5 minutes to revert the changes&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 19:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3397641#M1005737</guid>
      <dc:creator>elcommunication</dc:creator>
      <dc:date>2018-06-11T19:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3401003#M1005738</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;&lt;BR /&gt;Are you running 6.2.3.X and is it a cluster? &lt;BR /&gt;&lt;BR /&gt;In general 6.2.3 are MUCH faster than previous releases, and will give you a much better experience.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 08:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3401003#M1005738</guid>
      <dc:creator>Nikolaj Pabst</dc:creator>
      <dc:date>2018-06-18T08:33:35Z</dc:date>
    </item>
  </channel>
</rss>

