06-10-2020 01:59 AM - edited 06-10-2020 02:12 AM
Hello,
Just looking for some clarity around a deployment we are looking to do for a customer. So Basically they are looking to put in FTD 1140's at multiple sites. We will be looking to configure sub-interfaces on this and then the usual ACL's etc for each sub interface. If I remember FDM does not support configuring etherchannel, and that needs to be done via FMC?
Also, we have a FMC 6.2.3 installed in our core that we use for our firepower modules on our 5585's, DO you think it would be OK to bring the 1140s into the FMC? Or do we need to look at an upgrade for it to support the 1140s?
For Clarity, our FMC is a FMCv, and it looks like we use classic licenses, not smart licensing. Not sure if this would require an additional license for our FMCv?
06-10-2020 02:53 AM
Just looking for some clarity around a deployment we are looking to do for a customer. So Basically they are looking to put in FTD 1140's at multiple sites. We will be looking to configure sub-interfaces on this and then the usual ACL's etc for each sub interface. If I remember FDM does not support configuring etherchannel, and that needs to be done via FMC?
If you managed the FTD 1140 from the FMC in that case all the configuration will be push from the FMC. FMC with FTD 1140 etherchannel is supported here
Also, we have a FMC 6.2.3 installed in our core that we use for our firepower modules on our 5585's, DO you think it would be OK to bring the 1140s into the FMC? Or do we need to look at an upgrade for it to support the 1140s?
FMC and FTD will work fine. however you need to check with software version you running on FTD. but should not be an issue.
For Clarity, our FMC is a FMCv, and it looks like we use classic licenses, not smart licensing. Not sure if this would require an additional license for our FMCv?
FTD only work with smartnet license. if yo have a smartnet lic you can easily convert/get a token from the cisco smartnet.
06-10-2020 11:07 PM
A Firepower 1140 running FTD requires version 6.4+.
So, if you choose to manage it with FMC, the FMC must be upgraded.
Upgrading a virtual FMC to version 6.6+ requires increasing the allocated memory to at least 28 GB.
Newer versions of FDM allow you to configure both Etherchannels and subinterfaces.
You could also use Cisco Defense Orchestrator (CDO). That's a very attractive option for remote site deployments.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide