01-17-2024 01:43 PM
Dears
i have an 2 no's of physical FTD in HA and in multiple context that are splited as an internet firewall and DC Firewall, hence as i know it is not a good practice from the security perspective can i know the disadvantages for the same.
Thanks
Solved! Go to Solution.
01-17-2024 01:49 PM
@adamgibs7 there is no such thing as multi-context on FTD, this is only supported on ASA. There is a similar concept called multi-instance, where you can deploy multiple container instances on a single chassis that act as completely independent devices. As these devices are independant, they are as secure as the administrator configures them.
This is supported on Firepower 3100, 4100, 4200 and 9300 series hardware only.
01-17-2024 01:49 PM
@adamgibs7 there is no such thing as multi-context on FTD, this is only supported on ASA. There is a similar concept called multi-instance, where you can deploy multiple container instances on a single chassis that act as completely independent devices. As these devices are independant, they are as secure as the administrator configures them.
This is supported on Firepower 3100, 4100, 4200 and 9300 series hardware only.
01-17-2024 02:04 PM
Dears
The resources are shared on the physical boxes, if a perimeter firewall face an DDOS attack the firewall will reboot which will reboot all the instances, please correct me if i m wrong.
thanks
01-17-2024 02:09 PM
@adamgibs7 the hardware resources are not shared, instances allow hard resource separation, separate configuration management, separate reloads, separate software updates.
Read the link provided for more information.
01-17-2024 02:15 PM
this link describe that the logical device (instance) reload/reboot not whole physical box (FPR)
MHM
01-17-2024 02:04 PM
there is no context in FTD only, it only in ASA.
can you more elaborate
thanks
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide