cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
634
Views
1
Helpful
3
Replies

Backup Cisco Firepower Management Center for VMWare

aaron-rousch
Level 1
Level 1

Good Day Everyone.

I have a Cisco Firepower Management Center for VMware

Software Version 6.5.0.4
Operating System Cisco Fire Linux OS
Operating System Version 6.5.0

that is attached to an ASA5508 

Can I safely shut down the Firepower Management Center VM for a full backup, and Snapshot Maintenace, without disrupting traffic or policy enforcement?

Or is it when I temporarily bring down the Firepower Management VM, the Firewall will not function properly

Thank you for your time

-Aaron

PS if this is in the wrong Location, please let me know so i can change it ASAP

 

 

1 Accepted Solution

Accepted Solutions

First of all, you should update your firewall infrastructure to something current. Your software has been out of support for a very long time and doesn't receive any security updates. You are not effectively protecting your network with an outdated firewall.

For your question: Yes, you can shut down the FMC for maintenance. The firewalls run independently of them. You don't get any events from the sensors while the FMC is down. 

View solution in original post

3 Replies 3

First of all, you should update your firewall infrastructure to something current. Your software has been out of support for a very long time and doesn't receive any security updates. You are not effectively protecting your network with an outdated firewall.

For your question: Yes, you can shut down the FMC for maintenance. The firewalls run independently of them. You don't get any events from the sensors while the FMC is down. 

Thank you, Karsten.

I will temporarily shut down the FMC Virtual machine to create backups and snapshot maintenance now that i know the firewall will still filter traffic based on the current rules and polices in place.

 

Yes, i am aware that the Firewall is very much out of date. I have put in numerous requests to have the firewall replaced with a more current model and they do not want to spend the money at this time.

I would say it depends on your deployment. For instance if the FTD is using user ID policies and it happens to need a mapping to be provided by the FMC that won't work if the FMC is down. Other couple things come to mind are the scenario where the FTD needs to rely on the FMC for sandboxing results and logging to the FMC. I think those would also be affected when the FMC is down.

Review Cisco Networking for a $25 gift card