cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3451
Views
0
Helpful
1
Replies

De-register Firepower module from FMC and manage locally?

paul_murphy
Level 1
Level 1

Should FMC become unavailable (say ESX has multiple failures), is it possible to deregister Firepower modules from FMC and manage them locally for the duration of the outage?

What would be the implication of doing this?  Once ESX is up and running, we'd need to back-fill any policy changes I imagine. And I guess we'd need to redirect alerts somewhere else.

This is unlikely to be needed, I just need to describe the scenario.

 

 

 

1 Reply 1

Rahul Govindan
VIP Alumni
VIP Alumni

On Firepower threat defense (FTD) , changing the management from FMC to local (Firepower Device Manager) will most likely wipe out your config entirely. FTD devices can only be managed one way and not both. It would be easier to keep a regular backup of your FMC and restore it onto a new FMC (on a new ESxi host) in case of a failure. This way you can change management from one FMC to another and the FTD devices should pull the config from the new FMC as you had before.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: