03-12-2019 07:50 AM - edited 02-21-2020 08:56 AM
Hi guys,
One of our customers has a virtual FMC running on VMWare.
I had assumed that the best method for backing up the FMC would be to take VMWare snapshots.
However, I've just read this: https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fmcv/fpmc-virtual/fpmc-virtual-vmware.html#id_82728
Which states the following:-
###################################################
The following limitations exist when deploying for VMware:
Cisco Firepower Management Center Virtual appliances do not have serial numbers. The System > Configuration page will show either Noneor Not Specified depending on the virtual platform.
Cloning a virtual machine is not supported.
Restoring a virtual machine with snapshot is not supported.
Restoring a backup is not supported.
VMware Workstation, Player, Server, and Fusion do not recognize OVF packaging and are not supported.
###################################################
So this suggests that restoring from a snapshot is not supported. Does it just not work, or can it cause some kind of corruption (I don't see how) or what?
Without the ability to use snapshots, if the VM or host was to have some sort of catastrophic failure, the only option would be to re-install it from fresh, apply any patches and VDB to match what was running before and then restore from an FMC application backup. This would take much longer than a snapshot restore. :(
Anyone got any thoughts on this?
Thanks,
Matt.
03-13-2019 08:12 AM
Snapshots can break running systems with underlying databases. This is also true for ISE. If you shutdown the server and snapshot it while it's quiescent, it should be OK.
Just my suggestion - not TAC-approved or an official Cisco position.
11-21-2019 02:52 AM
11-21-2019 07:06 PM
Snapshots are not supported and definitely not recommended. I have personally tested this before and you run into a lot of issues especially if the snapshot was taken before any configuration changes/updates were made.
The best thing to do here is to utilize the supported backup/restore or move to an H/A solution which at the moment requires hardware appliances.
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide