<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Backup Device specific configuration for Firepower Threat Defense in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3349115#M1031339</link>
    <description>&lt;P&gt;The shortcoming you point out is one that I don't know any way around either. FTD devices have several operational capability shortcomings and this is one of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you noted, FMC doesn't allow you to snapshot an FTD device setup including the routing, inline sets etc. for restoration to a replacement unit. The only alternative you have for now is to redo them by hand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can only keep pressing Cisco to accommodate this functionality in a sustainable way in a future release. After all, traditional Firepower devices have had it for some time with the "Managed Device&amp;nbsp; Backup" feature (under System &amp;gt; Tools in FMC).&lt;/P&gt;</description>
    <pubDate>Thu, 15 Mar 2018 11:57:58 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-03-15T11:57:58Z</dc:date>
    <item>
      <title>Backup Device specific configuration for Firepower Threat Defense</title>
      <link>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3348604#M1031337</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I recently had the opportunity to use Firepower 4110 appliances for Backup and Restoration tests.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, I need someone to back me up on my findings or correct me where I went wrong.&lt;/P&gt;
&lt;P&gt;As far as I am concerned, you can create two Backup files. One for the FXOS and one for the FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If an appliance fails and a new one is delivered due to an RMA, I see the following tasks:&lt;/P&gt;
&lt;P&gt;- Bootstrap FXOS&lt;/P&gt;
&lt;P&gt;- Update FXOS if necessary&lt;/P&gt;
&lt;P&gt;- Upload last used FTD image file&lt;/P&gt;
&lt;P&gt;- Import last FXOS configuration&lt;/P&gt;
&lt;P&gt;FXOS will then go ahead and deploy the FTD device including the Manager Registration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The device has been registered with FMC beforehand and is still existing, but now marked as Failed/Disabled since all Health Checks fail.&lt;/P&gt;
&lt;P&gt;If the new FTD Logical Device is completely deployed, it is unable to contact the FMC. I had a packet capture running and actually saw communication on TCP/8305 between the appliance and the FMC. Encrypted data has been exchanged, but the FMC still claimed that there was no communication from the device.&lt;/P&gt;
&lt;P&gt;In order to push them towards eachother, I tried to reapply the Health Policy, ran the checks again and reconfigured the Manager in FTD by hand. Nothing worked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, hesistantly, I deleted the existing device from FMC and registered it. This worked fine, but(!) all Device specific configuration was lost. This includes (but is not limited to)&lt;/P&gt;
&lt;P&gt;- Interface configuration&lt;/P&gt;
&lt;P&gt;- Routing configuration&lt;/P&gt;
&lt;P&gt;- Inline Sets&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I often read that there is no need to do a device backup, because all information is stored in FMC, but the above content is definately lost, if an appliance is deleted from FMC. But without deletion, there is no Registration.&lt;/P&gt;
&lt;P&gt;FMC does not allow to register devices with the same IP address as an existing device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested this with FTD 6.1 and 6.2, FMC patched up to 6.2.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you guys have the same issues? How do you make sure that you can restore a failed device without having to configure IP addresses and routing by hand?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All the best,&lt;/P&gt;
&lt;P&gt;Marcus&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3348604#M1031337</guid>
      <dc:creator>MarcusFLey</dc:creator>
      <dc:date>2020-02-21T15:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Backup Device specific configuration for Firepower Threat Defense</title>
      <link>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3349115#M1031339</link>
      <description>&lt;P&gt;The shortcoming you point out is one that I don't know any way around either. FTD devices have several operational capability shortcomings and this is one of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you noted, FMC doesn't allow you to snapshot an FTD device setup including the routing, inline sets etc. for restoration to a replacement unit. The only alternative you have for now is to redo them by hand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We can only keep pressing Cisco to accommodate this functionality in a sustainable way in a future release. After all, traditional Firepower devices have had it for some time with the "Managed Device&amp;nbsp; Backup" feature (under System &amp;gt; Tools in FMC).&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 11:57:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3349115#M1031339</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-15T11:57:58Z</dc:date>
    </item>
    <item>
      <title>Re: Backup Device specific configuration for Firepower Threat Defense</title>
      <link>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3349319#M1031340</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you very much for your opinion on this matter. I highly appreciate it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think everyone appreciates your constant input to Firepower topics. I am gonna mark this as solved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Marcus&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 16:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/backup-device-specific-configuration-for-firepower-threat/m-p/3349319#M1031340</guid>
      <dc:creator>MarcusFLey</dc:creator>
      <dc:date>2018-03-15T16:11:55Z</dc:date>
    </item>
  </channel>
</rss>

