cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8534
Views
17
Helpful
5
Replies

Cisco FTD Multiple Context

netbeginner
Level 2
Level 2

Hello All,

 

We have to configure Cisco FTD 411X in multiple context mode . Will configuration steps and commands are same as like ASA, if not can anyone please share configuration example . is the command for swiitching between the context are also same in FTD or it's also different. 

 

Eg : ASA# changeto xyz context

 

Second, We have other Cisco FTD 21XX which need to be configure in ASA mode with multiple context. 

 

And both these FTDs have to be managed by FMC. Requesting if anyone can share :

 

1- FTD configuration for Multiple Context via CLI and CLI for changing context.

 

2- FTD configuration for Multiple context via FMC and steps to change between context from FMC itself. 

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

There are 2 Different things here, FTD 4K and 9K support Multi-instant as of ver  6.7 before, But latest version of 6.7 support Multi-context -  I have never tested(not got chance) - we do deployed multi instance.

 

FTD environment quite different compare to ASA, you have less access to CLI, Most of the things will be managed by FMC, until any specific command advised to run on command level as tac advise or monitoring purpose.

 

Rest all to be done using FMC only.

 

Multi-context requirement can be find here :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Marvin Rhoads
Hall of Fame
Hall of Fame

As @balaji.bandi noted, there is no such thing as a multi-context FTD device. Multiple instance is separate logical firewalls running on a single physical appliance. Each is managed and operated completely separately from the other.

hi marvin,

is cisco killing the ASA (on FTD)? i read the last ASA code would be 9.14.x.

can the FTD multi-context/instance be managed via CDO? or is it via FMC only?

@johnlloyd_13 The end of sales Firepower hardware appliance models like Firepower 4120/40/50 and 9300 with SM40/48/56 will not support ASA beyond 9.16.

The 41x5 and SM24/36/44 have no such planned limitation at this point as far as I know.

ASA software 9.14 is the last release for the ASA 5525/45/55 which are also end of sales.

@johnlloyd_13 

You mean running ASA on firepower hardware? No, not that I am aware of. ASA version 9.15 is available on 2100 series hardware, some older ASA hardware doesn't support newer ASA versions. Last I heard from Cisco is there are no plans to sunset ASA software yet.

 

Multi-context can only be managed via FMC AFAIK, whilst CDO can actually manage an FMC now, it has limited functionality. So right now you'd need an FMC

Review Cisco Networking for a $25 gift card