01-13-2025 10:00 PM
Hi,
I have one pair of FMC and on pair of FTD, currently FMC appliances in HA setup and we have successfully integrated with ISE pxGrid.
The question now is what will happen if the primary FMC fails, will FTD HA still receive the IP-to-SGT mapping from FMC, this is my doubt because the document says there is no auto failover for FMC HA, a manual promotion needed while the primary FMC fails. so, I'd like to know if the secondary FMC also sync and push down the IP-to-SGT mapping to FTD appliances in normal state.
Thanks
Solved! Go to Solution.
01-15-2025 01:48 AM
Hello,
i have this setup at my customer. And yes secondary FMC also update IP-to-SGT mappins on FTDs, as all FTDs have always 2 sftunnels open. One to primary and one to secondary FMC. So both FMCs are some kind of always active, you only enable the GUI to configure everything only on one FMC (like ISE).
01-14-2025 04:47 AM
If the primary management center fails, the Secondary management center propagates to managed devices user-to-IP mappings from the TS Agent identity source; and propagates SGT mappings from the ISE/ISE-PIC identity source. Users not yet seen by identity sources are identified as Unknown.
After the downtime, the Unknown users are re identified and processed according to the rules in your identity policy.
01-14-2025 06:34 AM
thanks for your reply.
We only use IP-to-SGT mapping in our environment.
That means only primary FMC propagate IP-to-SGT mappings in normal state, when the primary FMC fails, secondary FMC will automatically take over the "role" of propagating IP-to-SGT mappings to managed devices. During this period, User-to-IP mappings will be identified as unknown, as for IP-to-SGT mapping, it will not be affected.
Please correct me if I am wrong.
Thank you
01-15-2025 01:48 AM
Hello,
i have this setup at my customer. And yes secondary FMC also update IP-to-SGT mappins on FTDs, as all FTDs have always 2 sftunnels open. One to primary and one to secondary FMC. So both FMCs are some kind of always active, you only enable the GUI to configure everything only on one FMC (like ISE).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide