09-07-2021 06:50 AM
I am currently running FMC on VMWare ESXi 6.0. This FMC is managing two pairs of FTD clusters in two different Data Centers, and everything is working fine. I've been doing a nightly remote backup of the FMC. Now I have a requirement to test disaster recovery.
My plan is:
a- shutdown the production FMC,
b- bring up another instance of FMC with identical hostname & IP address with the exact FMC version specified in step a,
c- restore the backup to the new FMC in step b,
d- make a minor change to the policy,
e- deploy the policy to the pairs of FTD cluster,
I was told by TAC engineer, abeit sometime last years, that the process is NOT that simple. For one, the license will not be the same between the old and new FMC. Is that true?
Has anyone actually done this before can offer advises on this? do you have a step by step procedure on how to do this?
09-07-2021 07:12 AM
Should work as expected as per the steps you mentioned.
yes you need to get new License since the Serial number UUID changes (if you can change - not tried can be used same License)
when you move VM to VM, you need get First License move
Unregister FTD and Register again. should work as expected.
09-07-2021 07:37 AM
@balaji.bandi: "should work as expected", LOL.....
You mentioned "Unregister FTD and Register again". Will this result in an outage when I unregister and re-register. I had to do over again when shutdown the DR FMC and bring back the original FMC?
Restore FMC is so ugly and bad that it is not funny. Other vendors like Checkpoint and PaloAlto, restoring the configuration, you don't even have to unregister and re-register any of the Firewall modules.
09-07-2021 07:54 AM
i do manage other vendor you mentioned, so we are in cisco community and we are more discussing here cisco FMC. may be some of the features people desire to have need to go feature request.
i do not see any downtime here for doing FTD de-register and register not cause any issue, (if the IP not changed, you should not be doing that, but i mentioned to be safe side).
09-07-2021 08:12 AM
@balaji.bandi: so just to recap:
a- shutdown the production FMC,
b- bring up another instance of FMC with identical hostname & IP address with the exact FMC version specified in step a,
c- restore the backup to the new FMC in step b,
c1- get a new license from Cisco licensing due to UUID change,
d- make a minor change to the policy,
e- deploy the policy to the pairs of FTD cluster,
f- shutdown the new FMC,
g- bring up the original FMC in step a,
h- make a minor change in the policy,
i- deploy the policy to the pairs of FTD cluster,
Does it look right to you? I do NOT need to un-register and re-register the FTD, right?
09-07-2021 08:33 AM
why you want backup and restore, why not take snapshot and copy the vm to new dc bring up. (if you looking identical.)
One of the community member did get chance to change UUID on VM, not sure correct link, you can find thread some where in the security area, (if i get chance i will post)
09-07-2021 09:03 AM
snapshot and copy will NOT work here due to different version of ESXi
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide