<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The effect of a single-instance FMC failure in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/the-effect-of-a-single-instance-fmc-failure/m-p/4071729#M1069406</link>
    <description>&lt;P&gt;I hvae a new FMC 6.6 VM and 2 new 4115 NGFWs. In determining whether to use high availability for FMC, what is the effect of a failed single instance FMC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 6.6 FMC documentation only mentions you lose event data if you only have one FMC and it fails.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Event data streams from managed devices to both&amp;nbsp;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;s in the&amp;nbsp;&lt;SPAN class="searchMark primary"&gt;high availability&lt;/SPAN&gt;&amp;nbsp;pair. If one&amp;nbsp;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;&amp;nbsp;fails, you can monitor your network without interruption using the other&amp;nbsp;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/firepower_management_center_high_availability.html?bookSearch=true" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/firepower_management_center_high_availability.html?bookSearch=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An older thread mentions the same thing.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/fmc-6-0-down-what-happens-with-the-logging/m-p/2857651" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/fmc-6-0-down-what-happens-with-the-logging/m-p/2857651&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will my inspection and decryption on the 4115s still work normally if a single-instance FMC goes down?&amp;nbsp;&lt;/P&gt;&lt;P&gt;And is there an issue with just restoring a FMC VM from a snapshot?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2020 18:22:26 GMT</pubDate>
    <dc:creator>alandean</dc:creator>
    <dc:date>2020-04-22T18:22:26Z</dc:date>
    <item>
      <title>The effect of a single-instance FMC failure</title>
      <link>https://community.cisco.com/t5/network-security/the-effect-of-a-single-instance-fmc-failure/m-p/4071729#M1069406</link>
      <description>&lt;P&gt;I hvae a new FMC 6.6 VM and 2 new 4115 NGFWs. In determining whether to use high availability for FMC, what is the effect of a failed single instance FMC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The 6.6 FMC documentation only mentions you lose event data if you only have one FMC and it fails.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Event data streams from managed devices to both&amp;nbsp;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;s in the&amp;nbsp;&lt;SPAN class="searchMark primary"&gt;high availability&lt;/SPAN&gt;&amp;nbsp;pair. If one&amp;nbsp;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;&amp;nbsp;fails, you can monitor your network without interruption using the other&amp;nbsp;&lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/firepower_management_center_high_availability.html?bookSearch=true" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/660/configuration/guide/fpmc-config-guide-v66/firepower_management_center_high_availability.html?bookSearch=true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An older thread mentions the same thing.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/fmc-6-0-down-what-happens-with-the-logging/m-p/2857651" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/fmc-6-0-down-what-happens-with-the-logging/m-p/2857651&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will my inspection and decryption on the 4115s still work normally if a single-instance FMC goes down?&amp;nbsp;&lt;/P&gt;&lt;P&gt;And is there an issue with just restoring a FMC VM from a snapshot?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 18:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/the-effect-of-a-single-instance-fmc-failure/m-p/4071729#M1069406</guid>
      <dc:creator>alandean</dc:creator>
      <dc:date>2020-04-22T18:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: The effect of a single-instance FMC failure</title>
      <link>https://community.cisco.com/t5/network-security/the-effect-of-a-single-instance-fmc-failure/m-p/4071791#M1069408</link>
      <description>Hi,&lt;BR /&gt;If you only have 1 FMC you won't get central logging whilst the FMC is down, you won't be able to perform cloud lookups (AMP) and if you using user identity integration you will not receive updated ip/username bindings.&lt;BR /&gt;&lt;BR /&gt;VM snapshots are not supported, nor is HA on virtual appliances.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Wed, 22 Apr 2020 19:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/the-effect-of-a-single-instance-fmc-failure/m-p/4071791#M1069408</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-04-22T19:55:12Z</dc:date>
    </item>
  </channel>
</rss>

