cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
657
Views
0
Helpful
2
Replies

Cisco Firesight Policy

krunchyhchips
Level 1
Level 1

Hi All

I have a question around Cisco Firesight.

What is the recommendation around setting up Cisco Firesight Policies for multiple FWs.

Say if i have 20 x2 Active/Standby FWs doing pretty much same functionaility.

Shall I setup one policy for all of them or 20 separate policies.

Rose.

2 Replies 2

Jetsy Mathew
Cisco Employee
Cisco Employee

Hello krunchyhchips,

If you need to apply the same policies you can add multiple target devices to the same rule itself.

If you need to apply different policies or rule, then you need to create separate rules and policies.

Rate and mark the helpful posts.

Regards

Jetsy 

Oliver Kaiser
Level 7
Level 7

I think it really depends on your setup. Do you want to re-use policy rules for different firewalls? Do you need multi-tenancy?

Assuming you could re-use policy elements and want to be able to use your FMC for multiple tenants you could leverage domains and acp policy inheritance.

Create a child-domain under Global for your current tenant. Now create a base policy in global that can be re-used for multiple firewalls in your child-domain and set it as base policy for your individual firewall access-control-policies. Need to change a global policy rule - Just add it to the base policy. Need to add a firewall specific rule - just add it to your child policy.

Let me know if this answers your question

Review Cisco Networking for a $25 gift card