cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
858
Views
4
Helpful
5
Replies

FTD Multicontext

adamgibs7
Level 6
Level 6

Dears

i have an 2 no's of physical FTD in HA and in multiple context that are splited as an internet firewall and DC Firewall, hence as i know it is not a good practice from the security perspective  can i know the disadvantages for the same.

Thanks 

1 Accepted Solution

Accepted Solutions

@adamgibs7 there is no such thing as multi-context on FTD, this is only supported on ASA. There is a similar concept called multi-instance, where you can deploy multiple container instances on a single chassis that act as completely independent devices. As these devices are independant, they are as secure as the administrator configures them.

This is supported on Firepower 3100, 4100, 4200 and 9300 series hardware only.

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/multi-instance/multi-instance_solution.html

 

 

View solution in original post

5 Replies 5

@adamgibs7 there is no such thing as multi-context on FTD, this is only supported on ASA. There is a similar concept called multi-instance, where you can deploy multiple container instances on a single chassis that act as completely independent devices. As these devices are independant, they are as secure as the administrator configures them.

This is supported on Firepower 3100, 4100, 4200 and 9300 series hardware only.

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/multi-instance/multi-instance_solution.html

 

 

Dears

The resources are shared on the physical boxes, if a perimeter firewall face an DDOS attack the firewall will reboot which will reboot all the instances, please correct me if i m wrong.

thanks

@adamgibs7 the hardware resources are not shared, instances allow hard resource separation, separate configuration management, separate reloads, separate software updates.

Read the link provided for more information.

https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/multi-instance/multi-instance_solution.html

this link describe that the logical device (instance) reload/reboot not whole physical box (FPR)
MHM

there is no context in FTD only, it only in ASA. 
can you more elaborate
thanks 
MHM 

Review Cisco Networking for a $25 gift card