<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Firepower FTD 1010 High Availability Active and Standby in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firepower-ftd-1010-high-availability-active-and-standby/m-p/4457559#M1083233</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;From my experience i did a similar thing with FTD 2100 managed from FMC. If you doing from FMC make sure your in service firewall stay (make its as primary firewall) when doing a HA configure (From FMC GUI). I am sure the method for FTD2100 and 1010 is same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the reason saying keep the in service production as Primary as the Primary will push the configuration to Secondary firewall via FMC. make sure your layer 2 (VLAN) are solid and configured on both sides of DC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sure you have license for HA pair. here i get from cisco web &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/firepower_threat_defense_high_availability.html" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="editable"&gt;Smart License Requirements for HA&lt;/H3&gt;
&lt;P&gt;The following license requirements must be met for both physical and virtual FTDs:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Both devices in an HA pair must have&amp;nbsp;either a registered license, or an&amp;nbsp;evaluation license. If the devices are registered, they can be registered to different Cisco Smart Software Manager accounts, but the accounts must have the same state for the export-controlled functionality setting, either both enabled or both disabled. However, it does not matter if you have enabled different optional licenses on the devices.&lt;/LI&gt;
&lt;LI&gt;Both devices within the HA pair must have the same licenses during operation. It is possible to be in compliance on one device, but out of compliance&amp;nbsp;on the other if there are insufficient licenses.&amp;nbsp;If your Smart Licenses account does not include enough purchased entitlements, your account becomes Out-of-Compliance (even though one of the devices may be&amp;nbsp;compliant) until you purchase the correct number of licenses.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 31 Aug 2021 14:05:56 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2021-08-31T14:05:56Z</dc:date>
    <item>
      <title>Cisco Firepower FTD 1010 High Availability Active and Standby</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-ftd-1010-high-availability-active-and-standby/m-p/4457533#M1083232</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;Cisco Firepower FTD 1010, and due to the fact that we need high available network, i have question if i can order another FTD 1010, and configure both devises with High Availability Active and Standby.&lt;/P&gt;&lt;P&gt;Now i have one FTD1010 connected to 3 Cisco SG350.&lt;/P&gt;&lt;P&gt;Can i do a high availability Active and standby ?&lt;/P&gt;&lt;P&gt;Any information or from experience knowledge, or documentation will be appreciated&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 13:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-ftd-1010-high-availability-active-and-standby/m-p/4457533#M1083232</guid>
      <dc:creator>HaniAbuelkhair39121</dc:creator>
      <dc:date>2021-08-31T13:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower FTD 1010 High Availability Active and Standby</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-ftd-1010-high-availability-active-and-standby/m-p/4457559#M1083233</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;From my experience i did a similar thing with FTD 2100 managed from FMC. If you doing from FMC make sure your in service firewall stay (make its as primary firewall) when doing a HA configure (From FMC GUI). I am sure the method for FTD2100 and 1010 is same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the reason saying keep the in service production as Primary as the Primary will push the configuration to Secondary firewall via FMC. make sure your layer 2 (VLAN) are solid and configured on both sides of DC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sure you have license for HA pair. here i get from cisco web &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/firepower_threat_defense_high_availability.html" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="editable"&gt;Smart License Requirements for HA&lt;/H3&gt;
&lt;P&gt;The following license requirements must be met for both physical and virtual FTDs:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Both devices in an HA pair must have&amp;nbsp;either a registered license, or an&amp;nbsp;evaluation license. If the devices are registered, they can be registered to different Cisco Smart Software Manager accounts, but the accounts must have the same state for the export-controlled functionality setting, either both enabled or both disabled. However, it does not matter if you have enabled different optional licenses on the devices.&lt;/LI&gt;
&lt;LI&gt;Both devices within the HA pair must have the same licenses during operation. It is possible to be in compliance on one device, but out of compliance&amp;nbsp;on the other if there are insufficient licenses.&amp;nbsp;If your Smart Licenses account does not include enough purchased entitlements, your account becomes Out-of-Compliance (even though one of the devices may be&amp;nbsp;compliant) until you purchase the correct number of licenses.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 31 Aug 2021 14:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-ftd-1010-high-availability-active-and-standby/m-p/4457559#M1083233</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2021-08-31T14:05:56Z</dc:date>
    </item>
  </channel>
</rss>

