cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4463
Views
17
Helpful
25
Replies

Is FMCv supported on vmware ESXI 8.x?

lcaruso
Level 6
Level 6

FMC docs state it runs on ESXI 7.0 but nothing higher unless I missed something. 

25 Replies 25

robertyoung
Level 1
Level 1

I see 7.6 has landed but only for KVM.  Any release date for ESXi/vSphere?

We are hurtling towards 2025 with vSphere 8 almost 2 years old!

The posted 7.6 image for KVM is not for general use. It was posted publicly for use by a third party industry reviewer.

The official release is currently planned for September 2024.

robertyoung
Level 1
Level 1

So 7.6.0 landed in the last 24 hours or so.

I've carried out the installation to our vSphere 8 environment and so far it has been an absolute sh*tshow.  Any time I try to upload a backup of the previous installation, the web console tanks.  I've tried copying over the ACP from our 7.0.5 FMCv.... NOPE!... not in a format compatible with 7.6.

I can't carry out an IPU from 7.0.5 to 7.6.0 as it needs to be => 7.1.0 which I cannot move to on vSphere 8 as per this thread.

Given the length of time waiting we've had to endure, I'd have expected a far smoother experience.  Guess it may be time to start looking at other security appliance vendors!

You can upgrade 7.0.x to 7.4.2 and then upgrade your managed devices to the same. Upgrade FMC 7.4.2 to 7.6 while it's still on your vSphere 7 host. Then you can migrate it to your vSphere 8 host.

That does not address the apparent instability in the 7.6.0 release. Web console tanking and failing to recover in a timely manner, meaning a restart of the appliance is necessary to recover only for it to happen again is not an acceptable release. We've waited, (slightly) patiently for this release only for it to demonstrate a capacity for instability.

vSphere 6, 7 or 8, it matters not a jot.

That does not address the apparent instability in the 7.6.0 release.  Web console tanking and failing to recover in a timely manner, meaning a restart of the appliance is necessary to recover only for it to happen again is not an acceptable release.  We've waited, (slightly) patiently for this release only for it to demonstrate a capacity for instability.

 
vSphere 6, 7 or 8, it matters not a jot.

robertyoung
Level 1
Level 1

Update to 7.6.0 carried out this morning.  One click on a menu item and it completely tanks the web interface.

@Marvin Rhoads this is completely unacceptable.  We've waited 18 months for the ability to run FMCv in a vSphere 8 environment and one click into the menu structure immediately after an update and we lose the ability to manage our devices.  Thank <insert expletive or name of chosen deity here> we have not updated our FTD devices to 7.6 yet!

The conversation with TAC should be "interesting".

You should definitely take this up with Cisco TAC. I have upgraded 3 different productions FMCs to version 7.6 in the past week and not encountered any such issues to date.

I also ran the beta version in my lab (on ESXi for several months with only minor issues (mostly cosmetic rendering issues in the new magnetic framework user interface).

IFS
Level 1
Level 1

Thanks to this thread, I was able to halt the upgrade to ESXi 8.0 a short time ago before it became an issue with our FMCv.  I've reviewed the compatibility matrix many times when updating FMCv, but I luckily checked it before others on our team were going to update ESXi.

We're still running the recommended starred release of 7.2.8 FMCv and FTD.  I know others here would like to get ESXi updated to 8.0 sooner rather than later, but I'm always hesitant to update to a bleeding edge release such as 7.6.0.

@Marvin Rhoadsyou mentioned that it's been stable for you so far.  I've read in the past that it's not supported to do a vMware snapshot as a plan of recourse and that I better have good backups ready to go in case of a failure, but honestly I'd rather not have the need to stand up a new FMCv server.  The plan is to do an in place upgrade to 7.6.0 when I can get a sense that others are having good experiences.

So, any recommendations on where to get good feedback on the reliability and bugs in 7.6.0 other than the bug search tool?  I'll let it continue to bake for a bit before pulling the trigger, but additional feedback is always helpful.

removed

@IFS  I am up to 10 FMCs upgraded so far (a couple of HA pair of FTDs as well) with only one minor issue (due to pre-existing problem) that TAC was able to quickly fix.

Review Cisco Networking for a $25 gift card