cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2672
Views
10
Helpful
10
Replies

FMC appliance vs virtual

Dawood Jabbar
Level 1
Level 1

hello

 

i will  buy 2 FTD2130 and will work as HA but i want know what is the best form management this devices 

by FMC appliance or FMC Virtual , and in future can i upgrade RAM of  FMC appliance or i cant 

 

10 Replies 10

Marvin Rhoads
Hall of Fame
Hall of Fame

FMC hardware appliance RAM and hard disk drive are fixed sizes and cannot be upgraded.

FMC VM memory can be upgraded (not disk) but the newest version already requires 28 GB (32 GB recommended) so it's not likely you would need to upgrade it later.

The primary difference functionally is the amount of events each platform can store. Refer to the product data sheet for details:

https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html?cachemode=refresh

thank you for your reply

 I'm afraid Cisco in future  release newest version like 7.0 and required more RAM then 32G 

and my main question is from your experience  the appliance is  Faster handling and response from the virtual 

As long as you spec your VM with the correct specifications to your requirements, the vFMC can handle anything an appliance FMC can.  What you need to be careful of when setting it up is that the FMC should have dedicated resources and not share the resources with other VMs.  If you share the resources you can run into performance issues.

--
Please remember to select a correct answer and rate helpful posts

the deployment time is the same on appliance and Vm or the appliance will be faster    

This depends a little on how you look at it.
Appliance you will need to wait on delivery time while VM all you need is to download the software and you are ready for depoloyment.

if you have both the appliance and VM infront of you when you start deployment then the appliance will be faster... depending on what preparations you have done beforhand you van cut some time off the deployment of VM.

--
Please remember to select a correct answer and rate helpful posts

now i'm working on test lab 2  FTDv  and FMCv and when i do any configuration change  i should wait 2 mint before see the effect of my configuration change so this time will be short to 1 mint or less in real devices 

FMCv and FTDv  ruining on 6.3 version 

and this 2 mint is long time  especially when compared to ASA or PaloAlto or Fortigate   

I agree that deployment time for the FTD is quite horrible.  The amount of time deployment takes will depend on the size of your configuration also.  Prior to 6.3 deployment for one of my clients, for a simple ACP entry change took close to 5 minutes?  We have recently upgraded to 6.5 and the deployment time has improved to around 2 minutes, but there is still a lot of room for improvement.  I totally agree that 2 minutes for a deployment is way to long.

I have had a few discussions with TAC regarding this and they do not see the deployment time as an issue and pretty much point to the size of our configuration as being part of the issue.

From my discussions with TAC, it sounds like Cisco is working to reduce this deployment time.  I guess time will tell.

--
Please remember to select a correct answer and rate helpful posts

so from your experience do you recomanded  the FMC appliance or appliance will not make any  difference 

The functional difference is primarily in the system capacity. Until the FMCv300 was released recently all FMCv were relatively limited in the number of events they could store.

The other reason people choose the hardware appliances is due to inability or unwillingness to rely on a virtualization infrastructure for their security management and monitoring. some clients may be Hyper-V only or have a policy saying no new on-premise VMs (i.e. all net new must be cloud-based).

ida71
Level 1
Level 1

The biggest difference unfortunately is NONE.  I had previous experience with the vFMC on a system that was well specified & the GUI response was atrocious so when given the opportunity to acquire FMC's I went for the 1600 appliance, on the basis that it must be optimized for its role. NUTS I was wrong, its just as crap. The GUI response time I think is the worst I have ever seen for a vendor product. You learn quickly to right click open in new tab, then flick back & forth. If PC OS worked this slow, we would still be using pen & paper !

Review Cisco Networking for a $25 gift card