cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
480
Views
3
Helpful
5
Replies

Cisco FTD lost connection to FMC, what will happen to the IPS eventlog

Freemen
Level 1
Level 1

lets say FMC down for 1 day, after FMC up, will the 1 day event send back to FMC? 

will it have any datalost?

1 Accepted Solution
5 Replies 5

Thanks for the info

Marvin Rhoads
Hall of Fame
Hall of Fame

As implied by @tvotna , yes. You will most likely lose a record of events as the FTD device is not designed to store a large number of events locally.

You will most likely lose a record of events as the FTD device is not designed to store a large number of events locally.

so does it storoes some ? how much ? will they be sent back to fmc when its up ?

On managed devices events are stored in files. Yes, events are sent to FMC when connectivity between managed device and FMC is restored, unless events are drained from files, if the number of events exceeds certain limit. Different event types have different limits. Use "show disk-manager" and this article for explanations:

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/216081-troubleshoot-drain-of-fmc-unprocessed-ev.html

 

Review Cisco Networking for a $25 gift card