Hi,
If there are 2 instances for 2 customers on 4100 series firewall. Is it possible to assign specific resources to a specific customer also for IPS?
can anyone provide any cisco documentation ?
Mateen
Solved! Go to Solution.
You can use multi-instance mode to achieve "real" multi tenancy on FPR4100 / 9300. That way every virtual instance received dedicated cpu cores, memory and disk space. Splitting resources within a single instance is not possible, for example you cannot provision a virtual instance running Firepower Threat Defense and use 20% of the cpu cores for Customer A traffic and 50% of cpu cores for Customer B traffic. For a clean seperation you musst assign a dedicated instance to each customer (... atleast if you really need resource reservations) and a seperate data/control/mgmt plane for each customer
here is multi tenancy deployment and configuratiion guide :
If you got access to cisco Live Presentation look one of the document is good for reference :
BRKACI-3004
Can IPS resources also divided ?
I have not deployed, yes and hope so.
heard that IPS use shared resources when needed so it is not recomended to run IPS when firepower is shared with other customers. Cannot find any documentation.
You can use multi-instance mode to achieve "real" multi tenancy on FPR4100 / 9300. That way every virtual instance received dedicated cpu cores, memory and disk space. Splitting resources within a single instance is not possible, for example you cannot provision a virtual instance running Firepower Threat Defense and use 20% of the cpu cores for Customer A traffic and 50% of cpu cores for Customer B traffic. For a clean seperation you musst assign a dedicated instance to each customer (... atleast if you really need resource reservations) and a seperate data/control/mgmt plane for each customer