07-05-2020 10:19 AM
Hi Experts,
I would like to upgrade from virtual FMC to an appliance based FMC.
IMO, the appliance always wins, but i need to build a business case for this shift. I've noted a few points to justify this requirement, but i need a lot more to convince the stakeholders that its the right move to take.
Any further data will be very much appreciated.
My challenge is that all the above issues mostly point towards the log retention. How do i justify to the business that the Appliance FMC is the best for the organisation even though we are using SEIM solutions like Splunk in our environment.
I have attached a pic i have received of the internet that explains the different features that are distributed over different layers for your reference.
TIA,
Shabeeb
Solved! Go to Solution.
07-05-2020 01:20 PM
Ultimately the answer to your question is based on how large the network is (how much traffic will be logged and number of FTDs to manage).
The other thing to consider is that you need to Thick provision resources to the vFMC. If the vFMC is sharing resources with other VMs this will drastically affect performance on the FMC. You also have to make sure that the interface on the vFMC is configured to support 10Gig or you will run into a possible bottle-neck issue.
Functionality wise, other than lack of ability to configure it in an HA pair, vFMC can do everything an appliance FMC can do. For example, the FMCv300 can be compaired to the FMC 2600 appliance as long as you allocate the correct amount of resources.
07-05-2020 10:44 AM
Currently you cannot configure the virtual FMC in HA, meaning if during an outage or upgrade you’ll be unable to manage the FTDs, receive logs nor perform cloud lookups, if using AMP.
07-05-2020 11:11 PM
07-05-2020 01:20 PM
Ultimately the answer to your question is based on how large the network is (how much traffic will be logged and number of FTDs to manage).
The other thing to consider is that you need to Thick provision resources to the vFMC. If the vFMC is sharing resources with other VMs this will drastically affect performance on the FMC. You also have to make sure that the interface on the vFMC is configured to support 10Gig or you will run into a possible bottle-neck issue.
Functionality wise, other than lack of ability to configure it in an HA pair, vFMC can do everything an appliance FMC can do. For example, the FMCv300 can be compaired to the FMC 2600 appliance as long as you allocate the correct amount of resources.
07-07-2020 02:02 PM
07-08-2020 11:04 AM
As for the logging, the FMC is set to default to a very low log retention. If you go to System > Configuration > Database and find the Database you want to have a longer log retention for and increase the Maximum Connection Events. I have mine set to 100,000,000 but I have read of others that have this sett to 1 billion. Before changing this be sure you have enough storage space on your VM so you don't use up all the space for logging.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide