10-17-2024
02:30 PM
- last edited on
10-17-2024
03:54 PM
by
shule
Need to migrate off of EoL physical FMC devices for managing our FTD firewalls. Am currently weighing going on-prem vFMC vs, cloud delivered FMC via CDO.
Anyone gone through this scenario and have pros/cons for either side?
10-18-2024 02:23 AM
I think one of the biggest advantageous with cdFMC is that you don't have to worry about having an infrastructure in your environment to host it, how to maintain it, uptime, applying updates and patches, nor running a backup. All these admin works will be taken care by Cisco. However, there are a few limitations that you should consider before moving to cdFMC listed in the link below:
Another thing you might want to consider is licensing. cdFMC requires CDO licenses and if you want more storage for logs I think that has an additional license requirement. If the above limitations are not applicable in your case then I think moving to cdFMC would be a good choice.
Here is another link that expands all the cdFMC topics that you might find helpful:
10-18-2024 05:31 AM - edited 10-18-2024 06:28 AM
Adding to @Aref Alsouqi's good advice, the license for SAL (Security Analytics and Logging) can be pricey. Otherwise, cdFMC is a pretty attractive option. You can use an on-prem FMCv for logging only (or log to a SIEM or syslog server) as an option when moving to cdFMC.
10-26-2024 08:59 PM
Migrating from EoL physical FMC devices to either an on-premises virtual FMC (vFMC) or a cloud-delivered FMC through Cisco Defense Orchestrator (CDO) offers distinct advantages and limitations for managing FTD firewalls. Here's a breakdown:
Pros:
Cons:
Pros:
Cons:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide