<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deploying FTDv on prem vs cloud in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deploying-ftdv-on-prem-vs-cloud/m-p/4859113#M1101800</link>
    <description>&lt;P&gt;Firewalls installed in the cloud are almost always used to secure access to and from resources in that same cloud. While you could technically route your on-premise traffic via an IPsec tunnel to that cloud firewall and thence on to the Internet, it would not make sense for any use case I can think of. Performance would be decreased and you would pay for the traffic going into and coming out of the cloud that doesn't need to go there in the first place.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2023 04:48:37 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2023-06-21T04:48:37Z</dc:date>
    <item>
      <title>Deploying FTDv on prem vs cloud</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftdv-on-prem-vs-cloud/m-p/4859084#M1101799</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently in the process of building the network infrastructure for one of our clients, and the IT management is considering deploying FTDv (Firepower Threat Defense virtual) in a public cloud, specifically on an ESXi server. I have a few questions regarding this:&lt;/P&gt;&lt;P&gt;1. Is it possible to deploy FTDv in the cloud to protect the LAN network on-premises?&lt;BR /&gt;2. If FTDv is deployed in the cloud, how would the traffic flow work? For example, if a user on-premises wants to ping 8.8.8.8, would the packet go through an IPsec tunnel to the cloud network and then be subjected to NAT from the inside to the outside interface of the FTDv?&lt;BR /&gt;3.&amp;nbsp;&lt;SPAN&gt;Is it an ideal and common design practice to deploy FTDv in the cloud, particularly if the client lacks sufficient resources and powerful physical servers on-premises? Or should I advise them to invest in a physical server and deploy FTDv on-premises?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 01:58:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftdv-on-prem-vs-cloud/m-p/4859084#M1101799</guid>
      <dc:creator>MuathA.</dc:creator>
      <dc:date>2023-06-21T01:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deploying FTDv on prem vs cloud</title>
      <link>https://community.cisco.com/t5/network-security/deploying-ftdv-on-prem-vs-cloud/m-p/4859113#M1101800</link>
      <description>&lt;P&gt;Firewalls installed in the cloud are almost always used to secure access to and from resources in that same cloud. While you could technically route your on-premise traffic via an IPsec tunnel to that cloud firewall and thence on to the Internet, it would not make sense for any use case I can think of. Performance would be decreased and you would pay for the traffic going into and coming out of the cloud that doesn't need to go there in the first place.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 04:48:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deploying-ftdv-on-prem-vs-cloud/m-p/4859113#M1101800</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-06-21T04:48:37Z</dc:date>
    </item>
  </channel>
</rss>

