cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
2607
Views
10
Helpful
5
Replies
mateens
Beginner

IPS resources on Firepower

Hi,

If there are 2 instances for 2 customers on 4100 series firewall. Is it possible to assign specific resources to a specific customer also for IPS?

can anyone provide any cisco documentation ?

 

Mateen

1 ACCEPTED SOLUTION

Accepted Solutions
Oliver Kaiser
Rising star

You can use multi-instance mode to achieve "real" multi tenancy on FPR4100 / 9300. That way every virtual instance received dedicated cpu cores, memory and disk space. Splitting resources within a single instance is not possible, for example you cannot provision a virtual instance running Firepower Threat Defense and use 20% of the cpu cores for Customer A traffic and 50% of cpu cores for Customer B traffic. For a clean seperation you musst assign a dedicated instance to each customer (... atleast if you really need resource reservations) and a seperate data/control/mgmt plane for each customer

View solution in original post

5 REPLIES 5
balaji.bandi
VIP Guru

here is multi tenancy deployment and configuratiion guide :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/multi-instance/multi-instance_solution.html

 

If you got access to cisco Live Presentation look one of the document is good for reference :

 

BRKACI-3004

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

mateens
Beginner

Can IPS resources also divided ?

 

 

balaji.bandi
VIP Guru

I have not deployed, yes and hope so.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

mateens
Beginner

heard that IPS use shared resources when needed so it is not recomended to run IPS when firepower is shared with other customers. Cannot find any documentation.

Oliver Kaiser
Rising star

You can use multi-instance mode to achieve "real" multi tenancy on FPR4100 / 9300. That way every virtual instance received dedicated cpu cores, memory and disk space. Splitting resources within a single instance is not possible, for example you cannot provision a virtual instance running Firepower Threat Defense and use 20% of the cpu cores for Customer A traffic and 50% of cpu cores for Customer B traffic. For a clean seperation you musst assign a dedicated instance to each customer (... atleast if you really need resource reservations) and a seperate data/control/mgmt plane for each customer

Create
Recognize Your Peers
Content for Community-Ad