cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Bookmark
|
Subscribe
|
2104
Views
0
Helpful
8
Replies

FMCv clonning

AndrewM
Level 1
Level 1

Hello all,

We have two physical vSphere 6.0 hosts. One is a primary host which contains production VMs and another is a backup host for backup VMs. Production FMCv is up and running on primary host and connected to two ASA5516-X physical device and one Firepower 2120 Thread Defense physical device.

Now we are thinking to create backup FMCv  VM on backup host for disaster recovery or any problems/upgrades of primary host. VMware is allowing to clone virtual machines which is creating exact copy of MV. Do you see any problems with that approach if we clone FMCv from primary host to backup host? If yes what is better solution for this?

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

It's not a supported (by Cisco) approach but should work if you're careful.

 

I'd recommend stopping the application first so that the database doesn't have open transactions. Then clone the VM and finally restart the production server.

Thank you Marvin. I have also opened a ticket with TAC and they tried it in their lab and told me that it should work but I will need to reregister SFR modules and 2120 FTD device. I am now thinking about access control policies which already created for 2120 FTD  in FMCv and what happened with them after reregistration of device. Will they be deleted or will they be imported from device?

If it's truly cloned (same IP addresses - as you would with stretched L2 network) then re-registration shouldn't be necessary.

Yes two VMs are absolutely identical and located in the same subnet. The only difference in they are located on separate physical servers (VMware hosts).

Hi guys,

I did some test on that, below my procedure:

 

1 - cloned vFMC to another site

2 - changed ip address to cloned vFMC with "configure-network"

3 - changed hostname to cloned vFMC

4 - added dns record for cloned vFMC to dns servers

5 - cloned vFMC joined domain without any manual intervention

6 - added cloned vFMC to sourcefire AD agents

7 - cleaned device list on cloned vFMC

8 - unjoined a sensor on original vFMC (ASA5508 with SF module)

9 - joined the sensor to cloned vFMC

10 - added sensor started to work like a charm

Thank you Massimo.

I am not going to change IP address of FMCv. I just want to clone current FMCv to other physical VMware host(server), shut down current running FMCv and power on cloned FMCv. Nothing change except FMC virtual machine copied to other physical server. The same subnet, the same IP address, the same host name and so on.

 

Andrew

If it worked in my scenario, which was much more challenging than yours, I guess it should work for you also.

Anyway, be so kind to share your experience once done.

  

Hi Massimo Baschieri,  I know this is an older post but thought I would take a shot and ask anyways.  Before you clone the FMC did you to shutdown anything or just clone as it ran normally? We have some old ASA 5545 with SFR modules and would like to move them on to a temporary clone FMC. Then eventually I will shut them down as we just purchase 3105s.  
Thanks.

Review Cisco Networking for a $25 gift card