07-27-2023 08:20 AM
Hi Cisco Firepower experts,
I am preparing a FMC migration from old 1000 model to 1600 model. Got 2 questions.
1. Can the target FMC use a different MGMT IP other then the existing one?
2, The FMC is sending logs to SIEM, during the cutover, would the event log be lost for a few minutes? or the FTD will keep the log locally, and once the FTD re-establishes communication with FMC, the logs will then be sent out, so technically no log will be missed on the SIME side?
Thanks
Solved! Go to Solution.
07-27-2023 10:37 AM
1. Technically yes, but you don't want to go there since it makes the work 10x as much. Model migration is designed to keep the same IP on the new FMC.
2. FTD will retain events locally in queue if they are destined for FMC. However syslog events from FTD devices are generally sent out directly via UDP and not queued. Syslog from FMC based on incoming FTD events follow that model. eStreamer is tcp based and will drain the queue once the events start coming in again.
07-27-2023 10:37 AM
1. Technically yes, but you don't want to go there since it makes the work 10x as much. Model migration is designed to keep the same IP on the new FMC.
2. FTD will retain events locally in queue if they are destined for FMC. However syslog events from FTD devices are generally sent out directly via UDP and not queued. Syslog from FMC based on incoming FTD events follow that model. eStreamer is tcp based and will drain the queue once the events start coming in again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide