<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower deployments really slow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/4149587#M1073823</link>
    <description>&lt;P&gt;The latest release is currently 6.6.1. You will find that 6.5 and 6.6 both offer improvements in deployment speed over 6.4.x. 6.7 improves even more.&lt;/P&gt;
&lt;P&gt;6.6 also introduced an entirely new underlying database on FMC - monetDB. It makes resource-intensive tasks on the GUI much quicker.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2020 08:26:09 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-09-11T08:26:09Z</dc:date>
    <item>
      <title>Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094067#M1005719</link>
      <description>&lt;P&gt;I have new pair of NGFW 2110's. &amp;nbsp;I have a virtual FPMC. &amp;nbsp;This is a new build with relatively few rules (10) and NAT statements (14). &amp;nbsp;If I make a simple change to the policy and deploy it, it seems to take a really long time. &amp;nbsp;I'm regularly seeing 7+ minutes. &amp;nbsp;Is this normal? &amp;nbsp;Why? &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094067#M1005719</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2019-03-12T13:29:15Z</dc:date>
    </item>
    <item>
      <title>I'd expect under a minute</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094068#M1005720</link>
      <description>&lt;P&gt;I'd expect under a minute unless:&lt;/P&gt;
&lt;P&gt;a. A congested WAN is between your FMC and the sensors or&lt;/P&gt;
&lt;P&gt;b. The FMC is on underpowered compute resources (check the FMC status page for details).&lt;/P&gt;
&lt;P&gt;I'd recommend opening a TAC case to have them drill into the root cause if neither of the above is the case.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:31:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094068#M1005720</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-15T02:31:22Z</dc:date>
    </item>
    <item>
      <title>FMC and Management port of</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094069#M1005721</link>
      <description>&lt;P&gt;FMC and Management port of both firewalls is on the same LAN. &amp;nbsp;FMC is virtual on a UCS that is currently way under utilized. &amp;nbsp;I'm seeing that the only statistic that is high on the FMC statistics page is that Memory is at 80%. &amp;nbsp;Can I simply add more memory since it was an OVF deployment?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094069#M1005721</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2017-08-15T02:46:17Z</dc:date>
    </item>
    <item>
      <title>You can shutdown the server,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094070#M1005722</link>
      <description>&lt;P&gt;You can shutdown the server, add memory to the VM and restart but I was thinking more about CPU and storage IOPS. If it has the recommended 8 GB you may get some incremental improvement by going up to 12 or 16 GB but a deployment would not normally be a memory-intensive process.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094070#M1005722</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-15T02:50:39Z</dc:date>
    </item>
    <item>
      <title>I agree.  But CPU is fine and</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094071#M1005723</link>
      <description>&lt;P&gt;I agree. &amp;nbsp;But CPU is fine and storage has a long way to go before I am pushing IOPS. &amp;nbsp;It's a Nimble / Cisco Smartstack.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094071#M1005723</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2017-08-15T02:52:38Z</dc:date>
    </item>
    <item>
      <title>Are you running 6.2.1 with</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094072#M1005724</link>
      <description>&lt;P&gt;Are you running 6.2.1 with the 2110s?&lt;/P&gt;
&lt;P&gt;I haven't done any production deployments of those and there may be a not yet publicly-documented bug. I know 6.2.2. is about to be released - I'd reach out to the TAC to see if they can shed some light.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 02:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094072#M1005724</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-08-15T02:56:53Z</dc:date>
    </item>
    <item>
      <title>Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094073#M1005725</link>
      <description>&lt;P&gt;Yes, 6.2.1. &amp;nbsp;I will open a case.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 03:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3094073#M1005725</guid>
      <dc:creator>ncowger</dc:creator>
      <dc:date>2017-08-15T03:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198774#M1005726</link>
      <description>&lt;P&gt;what did you find out ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am seeing the same thing on a pair of 2120 with a vFMC running 6.2.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when navigating in the FMC it is very slow especially when you go want to use Connection/events. deployents takes 5-10min&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2017 17:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198774#M1005726</guid>
      <dc:creator>danhed7400</dc:creator>
      <dc:date>2017-10-14T17:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198870#M1005727</link>
      <description>&lt;P&gt;Just did my first production 2110s last week. In this case we ran 6.2.2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found deployments to take about 1 minute. I recommend upgrading to 6.2.2. to see if that helps. Even if it doesn't, there are many bug fixes there for other things.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Oct 2017 02:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3198870#M1005727</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-15T02:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3201102#M1005728</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have installed a pair of 2110 (in HA) and running FMC 6.2.2 code.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The FMC is&amp;nbsp;taking about 8 to 11 minutes each deploy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the FMC health and everything is ok.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="listview_full"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TH nowrap="nowrap"&gt;CPU Usage - User&lt;/TH&gt;
&lt;TD&gt;0.10%&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TH nowrap="nowrap"&gt;CPU Usage - System&lt;/TH&gt;
&lt;TD&gt;0.07%&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***&amp;nbsp;This environment isn't in production, no data passing through&amp;nbsp;interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 18:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3201102#M1005728</guid>
      <dc:creator>Rodrigo Rosa da Silva</dc:creator>
      <dc:date>2017-10-18T18:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, 6.2.1.  I will open a</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3202086#M1005729</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May i know if you are using the hard appliance or virtual FMC?&lt;/P&gt;
&lt;P&gt;Because i tried upgrading my FMCv to 6.2.2 but still experience slow deployment timing on FTD 5506X&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Standalone deployment takes around 4mins and HA deployments takes around 8 mins.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 00:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3202086#M1005729</guid>
      <dc:creator>WC615</dc:creator>
      <dc:date>2017-10-20T00:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3308339#M1005730</link>
      <description>&lt;P&gt;Firepower 2110 HA, 6.2.2.1 code&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also taking 7+ minutes for each deployment. Somewhat frustrating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any progress on this?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 15:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3308339#M1005730</guid>
      <dc:creator>dspender</dc:creator>
      <dc:date>2018-01-09T15:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309177#M1005731</link>
      <description>&lt;P&gt;For anyone searching on this. Here is the result of my TAC Case - I have TWO Firepower 2110 devices in HA running on most recent code:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I reviewed the troubleshoot file and I was not able to find any issue.&lt;/P&gt;
&lt;P&gt;As I explained in my previous email this time depends on the bandwidth and the Policy (rules, sensors and so on). I do not consider this time - 7 minutes for deploy as a problem.&lt;/P&gt;
&lt;P&gt;Please let me know if you have any other concerns or questions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Business day hours:&amp;nbsp; Mon - Fri - 8AM - 5PM (EST)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;XXXXXXXXXXX&lt;/P&gt;
&lt;P&gt;Cisco Firewall TAC engineer&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 18:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309177#M1005731</guid>
      <dc:creator>dspender</dc:creator>
      <dc:date>2018-01-10T18:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309205#M1005732</link>
      <description>&lt;P&gt;I haven't deployed to 2110's but I agree that 7 minutes is excessive. I'd push back on the TAC and request escalation to get another pair of eyes on it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now I am working with a couple of vFTD instances and an FMC VM (all on the same ESXi host which is running exclusively SSD storage) and deployments complete in about 1-1/2 minutes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You had indicated this is a new deployment with minimal policies. Are they in production at this point? I ask because I'm wondering if them being in an HA pair is affecting the time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any possibility of network issues between your FMC and the appliances? You might grab a tcpdump or spanned capture during deployment and see if Wireshark shows any tcp retransmissions or such.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2018 18:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3309205#M1005732</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-01-10T18:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314615#M1005733</link>
      <description>&lt;P&gt;We run a few FTD devices, along with several ASA w/FirePower services and a vFMC.&amp;nbsp; I've found that the deployment times are very sporadic for FTD devices.&amp;nbsp; The two devices that have the longest deployment times are our 2110's running in Active/Failover.&amp;nbsp; Depending on the changes being made, they can take about up to 10 minutes.&amp;nbsp; I've found that 5 minutes is the average, especially for changes to NAT and Access Policy whereas VPN changes seem to push in just a few minutes.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've had several long talks and multiple tickets open for issues/questions with FTD, but I'm at the point where I'm just attributing this to platform maturity.&amp;nbsp; I'm at peace with the length of deployment due to the security the system provides us.&amp;nbsp; We used CSM to manage our ASA firewalls for a long time, so longer deployments I'm used to.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 16:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314615#M1005733</guid>
      <dc:creator>workforcesoftware</dc:creator>
      <dc:date>2018-01-19T16:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314648#M1005734</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm working with many different deployments and I would say 8 minutes with FMCv and HA pair 2110 is normal.&lt;/P&gt;
&lt;P&gt;There is a big difference on a empty box, stand alone or ha pair. ranging from 2 minutes to 10 minutes.&lt;/P&gt;
&lt;P&gt;I believe Cisco will be doing something about this in coming releases.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;br, Micke&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 17:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3314648#M1005734</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2018-01-19T17:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3315681#M1005735</link>
      <description>&lt;P&gt;It's the same for me on a physical FPMC 1000 with around 15 rules and some very basic NAT &amp;amp; HA configuration, for a single FPR2110 pair - somewhere between 5-7 minutes per deploy even with a single change. I wouldn't say this is a FMCv-specific issue at all and from the horses mouth I was told this was "normal".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's frustrating because under some circumstances&amp;nbsp;traffic may be dropped during a deploy (&lt;STRIKE&gt;the circumstances where this can happen are vague and the documentation has conflicting information with the on-box help, which has information that conflicts with other on-box help&lt;/STRIKE&gt; I just double-checked and it looks like the documentation has been updated to be clearer). We're scheduling any policy change for after-hours as a result, even if it's a single access policy item addition or removal.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2018 08:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3315681#M1005735</guid>
      <dc:creator>adammckay1</dc:creator>
      <dc:date>2018-01-22T08:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3316841#M1005736</link>
      <description>Yeah, I've also heard this is normal from several resources within Cisco.  The issue of traffic dropping on deployment is the biggest issue I have with the new system.  Gone are the days of making changes during production hours, with little to no impact on the end-user.  That was the one thing I loved the most about the ASAs, especially at our headquarters.</description>
      <pubDate>Tue, 23 Jan 2018 14:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3316841#M1005736</guid>
      <dc:creator>workforcesoftware</dc:creator>
      <dc:date>2018-01-23T14:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3397641#M1005737</link>
      <description>&lt;P&gt;I'm new into the ASA firepower stuff and I think the deployment times are really slow up to 5 minutes. I'm getting gray hair before they're done. And if I deploy a change on a live environment and figure out the rule breaks connectivity for my users it takes at least 5 minutes to revert the changes&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jun 2018 19:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3397641#M1005737</guid>
      <dc:creator>elcommunication</dc:creator>
      <dc:date>2018-06-11T19:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower deployments really slow</title>
      <link>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3401003#M1005738</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;&lt;BR /&gt;Are you running 6.2.3.X and is it a cluster? &lt;BR /&gt;&lt;BR /&gt;In general 6.2.3 are MUCH faster than previous releases, and will give you a much better experience.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 08:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-deployments-really-slow/m-p/3401003#M1005738</guid>
      <dc:creator>Nikolaj Pabst</dc:creator>
      <dc:date>2018-06-18T08:33:35Z</dc:date>
    </item>
  </channel>
</rss>

