04-20-2026 06:27 AM
I'm designing a standard FMC + FTD HA topology and trying to determine the best way to give the FMC internet access for Smart Licensing, AMP cloud, and VDB updates.
If I route the FMC's outbound traffic through the FTD data plane, it creates a "chicken-and-egg" scenario: the FMC cannot reach the internet to license itself or get updates until the FTD is fully deployed and passing traffic.
Is the standard real-world practice to just push a basic "bootstrap" config to the FTDs first so the FMC can get online? Or do most enterprise environments put the FMC on a completely separate firewall/ISP connection so it doesn't rely on the very FTDs it is managing?
Thanks for the input!
Solved! Go to Solution.
04-20-2026 01:11 PM
The FMC has an evaluation period of 90 days before it stops being able to deploy changes.
That should leave you enough time to get everything configured. I have never seen a deployment using another device for internet access than the device the FMC is managing.
Just make sure that the FMC can reach the FTD management IP without going through the firewall.
04-20-2026 11:56 AM
How about SCC/cdFMC instead?
04-20-2026 01:11 PM
The FMC has an evaluation period of 90 days before it stops being able to deploy changes.
That should leave you enough time to get everything configured. I have never seen a deployment using another device for internet access than the device the FMC is managing.
Just make sure that the FMC can reach the FTD management IP without going through the firewall.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide