cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8814
Views
66
Helpful
4
Replies

A classic : CDO vs FMC

Hi Everyone,

 

I would like to know some more information and feature comparison between CDO and FMC, I guess there is someone out there with my same questions.

 

I think we can recap into this simple bullet list

 

CDO

  • Why yes
  • Why no
  • Price?
  • How it works?

FMC

  • Why yes
  • Why no
  • Price?
  • How it works?

And a main question : is CDO the future and FMC something that will disappear?

Thank you!

4 Replies 4

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

I won't go in details on price point because I'm not able to do any estimate right now. However, if I recall correctly (this has to be verified with CCW or your local Cisco representative): Let's take FPR2110 as example.
- FMC for 2 devices is 800$ GPL
- CDO license would be around 1700$ GPL per device (For a FPR2110)

In addition to that, if you want to have a central logging point for these FTDs, you need to purchase Security Analytics and Logging (SEC) if with CDO. Pricing will be on number of Gb data log per day.

Now this is quick overview of pricing and this has to be viewed on a case by case basis because sometimes FMC makes more sense, sometimes CDO makes more sense.

FMC will manage only Firepower images (FTD or Firepower module Services). CDO is able to centrally manage your ASAs, FTD, Meraki security policies and AWS  VPC security policies.
For FMC, you need to have a local VM (with some resources like 32G RAM) and need to manage the redundancy as well. CDO is cloud based (could have a local VM with small resources to communicate with the cloud and not expose your devices management). You need to see CDO like the Meraki portal for Cisco Security Firewalls.

CDO for FTD is based on FDM capabilities meaning features limitations from FDM compared to FMC based managed devices will be still there.

With FMC you have much more report possibilities that you have today with CDO. However, SEC can be linked with your StealthWatch cloud account and go deeper into analysis.

There's no official statement saying CDO will replace FMC. There're here providing 2 different purposes and for now no-one will replace the other. But who knows for the future :-) 

 

Also you have some features available on CDO (migrating ASA to FTD) that's not included in FMC (you need to use the migration tool separately).

 

The other thing to take into consideration is when a feature come to FDM or ASA, it will take time before it's available back to CDO right now. Maybe this will change but this is the status today.

 

Devices managed by FMC have a sftunnel built from your FTD device to your FMC. If you re-image your FMC for any reason or remove it, you'll need to reimage your FTD and redo the config locally (no config migration from FTD FMC managed devices to FTD FDM locally managed).
With CDO, you centrally managed your devices but they will be kept as locally managed with FDM. If you decide to remove CDO, you will keep your config as is and continue working without impacting your business in terms of traffic.

So it depends more on what you need to be able to decide which solution fits better for you. 
If you have multiple FWs (ASAs and FTDs), I believe CDO will be a huge advantage instead of managing them manually.

 

Don't know if this answers a part of your questions


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi Francesco,

 

It helps a lot, thanks.

 

Actually I did not consider what you mentioned, the event analysis licensing :

 

https://docs.defenseorchestrator.com/Configuration_Guides/Monitoring_and_Reporting/Cisco_Security_Analytics_and_Logging

You're welcome. Please don't forget to rate and mark the answer as correct of what i provided answered your question.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

CDO is an amazing tool.  But please don't forget also that CDO is only available on the public Internet.  For customers who do not have access to or decide not to connect to the public Internet, CDO is not a management option.  FMC will be the on-prem management engine for long into the future.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card