cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
853
Views
5
Helpful
1
Replies

Firepower 9300 and a new security module

Maciej Waliszko
Level 1
Level 1

Hello,

I have two FP9300 devices and each of those boxes have an old security module - slot1 (two slots are empty).

Multi-instance deployment is used + HA failover FTD pair was configured between both 9300 devices.

Now I want to add a brand new security module to each of the boxes into slot 2 (but still preserve/leave the old security module). In addition to that I want to move the FTD logical devices into the new security modules (much more powerful compared to the old ones).

Is my understanding correct that I need to break HA on FMC and configure HA pair from scratch?

 

 

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

The new SMs will indeed need to be configured from scratch with new logical devices. They can match the current configurations (being careful to leave data plane interfaces shutdown) and then be swapped over by shutting down the interfaces on the current pair and bringing them up on the new pair.

Review Cisco Networking for a $25 gift card