cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1403
Views
0
Helpful
1
Replies

Best Design for Multiple Devices in FMC

dan hale
Level 3
Level 3

Hi All, I have a FMC running on version 6.2.2. Currently we have 2 4110's in an HA at one of our sites. We are replacing two HA ASA's at another remote site with 2 more 4110's which I plan to put in HA.

 

My question is I know I should have separate interface groups in the FMC for the new site but, should I also create a separate security zone for the new HA 4110's. Should I take it a step further and when I name my interfaces at the new site name them something completely different than inside, outside, DMZ which is what I have now at the production main site.

 

Any issues with the above?

 

Thanks,

Dan

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

There's no need to name them differently.

 

You can simply use a unique Access Control Policy. The original ACP targets the first HA pair and the new one targets the second.

Review Cisco Networking for a $25 gift card