07-20-2020 02:47 PM - edited 07-20-2020 02:49 PM
Hello,
I'm trying to stage an FTD appliance to replace an ASA with Firepower that is currently in production. The FMC that controls it is also controlling an FTD HA pair. What is the best way for me to stage the new FTD appliance without disrupting production?
Normally I just stage the FMC and sensor(s) in my lab, backup the customer FMC with Veeam, restore the Veeam backup to customer vmware server, turn down the customer's old FMC (if applicable), connect the new sensor/device (FTD or ASA) and then spin the new FMC up. However; this will be somewhat difficult because the FMC is running at a colo facility and the FTD is being deployed to a different site about 4 hours away. This poses a physical problem for me as I can't be on site at the colo facility should anything go wrong with the Veeam FMC restore. Also, I need to preserve the production FMC configuration so I don't lose the config for the FTD HA pair in production at the colo.
I have access to both networks remotely but I can't seem to figure out the best way to stage the replacement FTD without breaking production.
Some details:
User site: 5515-X ASA w/ FP (ver 9.8.4)
Colo site: vmware FMC 6.3.0.x, FTD 1140 HA pair
The ASA w/ FP is being replaced with an FTD 1140
Anyone have a proven strategy for this kind of scenario?
Thanks,
John
07-21-2020 07:12 PM
Why not just register the new FTD with the existing FMC? You can change the management address later if you need to do so once you've deployed it on site.
07-22-2020 09:43 AM
07-22-2020 11:03 PM
The methods Cisco recommended to us during partner training all involve being able to reach FMC one way or another - being on the same site, having access to FMC via a public IP, or having a site-site VPN that can reach the FMC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide