<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Secure Firewall 4225 Instance Sizing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5325560#M1122453</link>
    <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;I am trying to size the instances of a new multi-instance Cisco Secure Firewall 4225 FTD deployment and I'm confused regarding the amount of CPU/cores I can play with. The documentation states that the device has 128 cores and that the maximum number of instances is 15.&lt;/P&gt;&lt;P&gt;My simple math is that:&lt;BR /&gt;128 / 15 = 8.5 cores&lt;BR /&gt;&lt;SPAN&gt;So &lt;STRONG&gt;8 cores per instance&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;But at the same time, the minimum number of cores per context is 6:&lt;BR /&gt;128 / 6 ~= &lt;STRONG&gt;21 instances&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I can't find any reference in the documentation about the core distribution/reservation done by the device apart from each instance reserving 2 cores for management.&lt;/P&gt;&lt;P&gt;Anyone has any clues?&lt;/P&gt;</description>
    <pubDate>Fri, 29 Aug 2025 10:23:36 GMT</pubDate>
    <dc:creator>diecarvic</dc:creator>
    <dc:date>2025-08-29T10:23:36Z</dc:date>
    <item>
      <title>Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5325560#M1122453</link>
      <description>&lt;P&gt;Good day all,&lt;/P&gt;&lt;P&gt;I am trying to size the instances of a new multi-instance Cisco Secure Firewall 4225 FTD deployment and I'm confused regarding the amount of CPU/cores I can play with. The documentation states that the device has 128 cores and that the maximum number of instances is 15.&lt;/P&gt;&lt;P&gt;My simple math is that:&lt;BR /&gt;128 / 15 = 8.5 cores&lt;BR /&gt;&lt;SPAN&gt;So &lt;STRONG&gt;8 cores per instance&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;But at the same time, the minimum number of cores per context is 6:&lt;BR /&gt;128 / 6 ~= &lt;STRONG&gt;21 instances&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I can't find any reference in the documentation about the core distribution/reservation done by the device apart from each instance reserving 2 cores for management.&lt;/P&gt;&lt;P&gt;Anyone has any clues?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 10:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5325560#M1122453</guid>
      <dc:creator>diecarvic</dc:creator>
      <dc:date>2025-08-29T10:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5325593#M1122456</link>
      <description>&lt;P&gt;Check command under fxos scope&lt;/P&gt;
&lt;P&gt;Set cpus &amp;lt;&amp;lt;- this command assign cores per instance&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 29 Aug 2025 13:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5325593#M1122456</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-08-29T13:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326052#M1122485</link>
      <description>&lt;P&gt;So I found that I can get the core affinity using the following command in the ftd expert section:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;pmtool show affinity&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The device indeed has 128 cores:&amp;nbsp;60 for lina/data, 64 for snort, and 4 for (i assume) FXOS.&lt;/P&gt;&lt;P&gt;Still, it's impossible to know how many of each will be assigned to an instance beforehand unless there is a formula or table that specifies it, like this one that unfortunately does not contain any 42xx device.&lt;BR /&gt;&lt;A href="https://secure.cisco.com/secure-firewall/docs/appendix-1" target="_blank" rel="noopener"&gt;Data Plane and Snort Core Distribution Tables&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 10:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326052#M1122485</guid>
      <dc:creator>diecarvic</dc:creator>
      <dc:date>2025-09-01T10:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326058#M1122486</link>
      <description>&lt;P&gt;The compute you going to allocate based on the instance requirement and features you using. that is maximum instance that device can offer. based on the performance and usage of the FTD you increase the instance or compute resources, cisco may have tested instance in certain parameters(that may not not be suitable for production environment some times as per my view).&lt;/P&gt;
&lt;P&gt;Look at the admin guide more explained here :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/device-ops-logical-devices.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/device-ops-logical-devices.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Note : If this is single device not Cluster or HA - i would not take risking all eggs in one basket and expect to run as expected.&lt;/P&gt;
&lt;P&gt;some performance matrix for reference :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://selabs.uk/reports/advanced-performance-test-report-cisco-secure-firewall-4225-2025-05" target="_blank"&gt;https://selabs.uk/reports/advanced-performance-test-report-cisco-secure-firewall-4225-2025-05&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 07:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326058#M1122486</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2025-09-01T07:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326117#M1122490</link>
      <description>&lt;P&gt;Sorry I dont get it what is relate of NXOS with FTD ?&lt;/P&gt;
&lt;P&gt;How many instances you run ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 10:33:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326117#M1122490</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-01T10:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326122#M1122491</link>
      <description>&lt;P&gt;Sorry I meant to type FXOS.&lt;/P&gt;&lt;P&gt;My idea is to run 5 instances. Since the limiting factor will be data and not snort, I want to optimize sizing in that regard.&lt;/P&gt;&lt;P&gt;For instance lowering the core assignment in an instance from 36 to 34 or 32 if that would only lower the number of snort cores assigned to an instance of that size. And increasing the number of cores assigned to the other instances.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 10:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326122#M1122491</guid>
      <dc:creator>diecarvic</dc:creator>
      <dc:date>2025-09-01T10:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326124#M1122492</link>
      <description>&lt;P&gt;All four instances run same feature&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I.e. url filter' IPS' SI' ssl policy?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 10:43:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326124#M1122492</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-01T10:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Firewall 4225 Instance Sizing</title>
      <link>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326262#M1122512</link>
      <description>&lt;P&gt;I think this what you looking for&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://secure.cisco.com/secure-firewall/docs/firepower-multi-instance-performance" target="_blank"&gt;https://secure.cisco.com/secure-firewall/docs/firepower-multi-instance-performance&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 20:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-secure-firewall-4225-instance-sizing/m-p/5326262#M1122512</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-09-01T20:10:40Z</dc:date>
    </item>
  </channel>
</rss>

