<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simple FTD Question -- Are instantaneous changes possible? Yes or in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499667#M1084917</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290729"&gt;@brettp&lt;/a&gt; yes that is generally true, you do need to deploy the changes which take a few minutes. However since version 7.0 you do have dynamic objects, which allow you to push changes via API and take effect immediately without having to push policy. &lt;A href="https://integratingit.wordpress.com/2021/06/19/ftd-dynamic-objects/" target="_self"&gt;More info&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Gt5Yj7MgtG0&amp;amp;t=177s" target="_blank"&gt;https://www.youtube.com/watch?v=Gt5Yj7MgtG0&amp;amp;t=177s&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Nov 2021 18:29:45 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2021-11-08T18:29:45Z</dc:date>
    <item>
      <title>Simple FTD Question -- Are instantaneous changes possible? Yes or no?</title>
      <link>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499661#M1084916</link>
      <description>&lt;P&gt;Because Cisco is phasing out the ASA and moving to FTD, that would be the next logical upgrade in our environment. I have just started to scratch the surface and have been watching videos about FTD Hardware / OS. I learned that you have to make changes and then deploy them. In the videos, it's never instantaneous as was the case on the ASA hardware. It seems to take up to a few minutes for simple changes to take effect (IP address changes, Access Rule changes, etc.) I read on the Cisco website,&amp;nbsp;&lt;SPAN&gt;“&lt;/SPAN&gt;&lt;SPAN&gt;We&amp;nbsp;strongly&amp;nbsp;recommend you deploy in a maintenance window or at a time when interruptions will have the least impact&lt;/SPAN&gt;&lt;SPAN&gt;” because there can be dropped packets (and not just if/when Snort restarts.) Is that really the case? If I can not make a change on the fly that happens instantly, like updating an ACL, that is an instant deal breaker. Can someone who uses these FTD devices (with FTD OS, not ASA) in the real world answer this? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 18:15:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499661#M1084916</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2021-11-08T18:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Simple FTD Question -- Are instantaneous changes possible? Yes or</title>
      <link>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499667#M1084917</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290729"&gt;@brettp&lt;/a&gt; yes that is generally true, you do need to deploy the changes which take a few minutes. However since version 7.0 you do have dynamic objects, which allow you to push changes via API and take effect immediately without having to push policy. &lt;A href="https://integratingit.wordpress.com/2021/06/19/ftd-dynamic-objects/" target="_self"&gt;More info&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=Gt5Yj7MgtG0&amp;amp;t=177s" target="_blank"&gt;https://www.youtube.com/watch?v=Gt5Yj7MgtG0&amp;amp;t=177s&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 18:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499667#M1084917</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-11-08T18:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: Simple FTD Question -- Are instantaneous changes possible? Yes or</title>
      <link>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499686#M1084918</link>
      <description>&lt;P&gt;Hello! To add another hint, dropping packets by Snort engine restart is a very particular scenario. I don't know what kind of company do you manage but you rarely perceive the drops, so you shouldn't worry too much because there are different configurations to avoid that behavior.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/policy_management.html#concept_uc1_gtq_ty" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/policy_management.html#concept_uc1_gtq_ty&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 19:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499686#M1084918</guid>
      <dc:creator>#Mat</dc:creator>
      <dc:date>2021-11-08T19:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Simple FTD Question -- Are instantaneous changes possible? Yes or</title>
      <link>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499722#M1084919</link>
      <description>&lt;P&gt;Unlike ASAs (And many traditional network devices) where the configurations are stored in flat text file, FTD uses DBs under the hood. As a result, we will most likely never see configuration changes committed in similar fashion and speed to "wr mem" With that said, we are constantly working on optimizing the deployment mechanisms. Thus, with each new release, the amount of time required to deploy changes is improved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With regards to your 2nd topic: The deployment window will warn you if the pending changes will cause traffic interruptions. In addition, with the introduction of Snort3 (Firepower Threat Defense v7.0), we have eliminated most cases where snort restart is required.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 20:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-ftd-question-are-instantaneous-changes-possible-yes-or-no/m-p/4499722#M1084919</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2021-11-08T20:44:47Z</dc:date>
    </item>
  </channel>
</rss>

