cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
306
Views
0
Helpful
2
Replies

Cisco CDO vs FMC and installation locations.

Will Kirk
Level 1
Level 1

Hello y'all,

My company is about to implement 2 FPR-1140's to replace our current ASA's, and my superiors are planning on installing CDO directly on the Firepower appliances, as well as a separate VM for FMC.

My understanding is CDO is generally implemented as a SaaS application, or can be deployed locally on VMWare/ESXi, but is it possible to have CDO installed directly on the firepower appliance itself?
My other question is that is having FMC on a separate VM redundant in this case where we want to implement CDO?

Thank you to anyone who helps me out.

1 Accepted Solution

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

 

CDO is on cloud services - as per i know where is no on prem

FMC can be installed on Prem VM  / Physical and cloud also.

One of the VIP explained more here :

https://community.cisco.com/t5/network-security/a-classic-cdo-vs-fmc/td-p/4070116

also choose the right one :

https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5508X/asa-5508-5516-gsg/m_introduction.pdf

Note : things may have changed in recent version, check with partner always buying a solution.

 
My other question is that is having FMC on a separate VM redundant in this case where we want to implement CDO?

first i would check what can do and can not do, then make a plan, if i were you i go with FMC.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

 

CDO is on cloud services - as per i know where is no on prem

FMC can be installed on Prem VM  / Physical and cloud also.

One of the VIP explained more here :

https://community.cisco.com/t5/network-security/a-classic-cdo-vs-fmc/td-p/4070116

also choose the right one :

https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5508X/asa-5508-5516-gsg/m_introduction.pdf

Note : things may have changed in recent version, check with partner always buying a solution.

 
My other question is that is having FMC on a separate VM redundant in this case where we want to implement CDO?

first i would check what can do and can not do, then make a plan, if i were you i go with FMC.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for some of the clarification, I have a few additional questions if you don't mind.

With 2 FPR-1140's, can we run HA using FDM locally on both appliances while also managed by CDO? I've heard you used to not be able to do HA with FDM in the past, and I was curious if that is still true now.

Also, I've read that when we manage our FTD's using CDO, that a local VM deployment of FMC will not work alongside it, is that true?

Thanks.