Hi,
I am hoping somebody can elaborate on the Transfer Packet feature/option when adding a device to the FMC.
The Cisco document says this option is on by default and that it the FTD device sends packet data with the events to the Firepower Management Center. So does this mean that if the FTD device has 1 Gig of data traffic transiting the device, then the device also sends a full copy of the packet payload(s) to the FMC ie the FMC effectively receives 1 Gig (ish...) of data?
The Cisco documentation does not really explain what this feature is really doing and a post from Todd Lammle (https://www.lammle.com/blog/4685/installing-cisco-firepower-important-questions-answer-start/) seem to indicate that it is sending the full payload.
I am thinking of locating the FMC in a central DC and managing multiple FTD devices at other remote sites/DC's over the Internet and I am struggling to figure out what the inbound bandwidth hit is going to be at the FMC end, especially if each FTD device is sending a full copy of the payload of every packet.
Has anybody got any experience of using the Transfer packet feature/option that they could share with me please.
Rgds
John