03-12-2018 01:15 PM - edited 02-21-2020 07:30 AM
I am wanting to deploy a FTD virtual into Azure using the pre-built on the from Azure Marketplace. I want it to be in Routed Mode and to have an Inside, Outside, a DMZ interface, and finally an interface for Management.
It sounds like the FTDv only supports routing on TWO of the 4 available interfaces? I'm confused on this. Does the FTDv have limitations that the hardware FTD running on my 5506-X would have?
https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/azure/ftdv-azure-qsg.html
From the document:
03-12-2018 06:10 PM
Hello Lucas,
Looks like you are not the only one, there are many people out there who are really not happy with this limitation. We had a discussion last week with our Cisco accounts manager and they listed the 2 major limitations:
Out of total 4 interfaces, only 2 can be used as data interfaces.
second, FMC can not be installed on Azure, it has to be On-Prem or on AWS.
We are discussing the alternatives - a workaround or maybe another solution. If I have some good news, I will post it.
Good luck Azuring.!!
HTH
AJ
03-12-2018 06:32 PM
Hello,
I was digging more and actually found this video. It talks about how we can integrate more subnets with Firepower. It uses the UDR feature and forces all the other subnets to go through the Firepower and hence be inspected. It will handle both North-South Traffic and East-West Traffic.
https://www.youtube.com/watch?v=UBO2yRMYPA8
FYI, I have not tested it but will test it out soon.
HTH
AJ
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide