cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
825
Views
0
Helpful
5
Replies

where to find 'direction' on the FTD/FMC platform 7.x ?

Eddie in.Mass
Level 1
Level 1

good day all....so i'm here asking this question largely due to an Office365 hybrid roll-out that we are in midst of

and needing some outbound ruleset that points to *.office.com , etc....and then finding the only real way to do this is to spin up and create a VM to run CSDAC (dynamic attributes connector) , which is introduced in 7.0 / 7.1 / 7.2

to me, seems the 7.x branches of code (and new features) are coming along fast and furious...and while i'm excited to READ about the new(est) features, i also don't want to get in to some crash-and-burn situations like i've read about in The Community.

where is a place that aggregates real-world feedback on customers experience (good/bad) about , 7.1.x and forward ?

i have searched in these threads and not nearly as much content as i'd like ?

do i just send ALL my questions to Marvin Rhoades ? (a compliment to ya sir) ....or what....

 

ok....thnx

E

5 Replies 5

Marvin Rhoads
Hall of Fame
Hall of Fame

@Eddie in.Mass the Firepower release strategy described here: https://www.cisco.com/c/en/us/products/collateral/security/firewalls/bulletin-c25-743178.html

7.0.x is under the "Extra Long Term Release" category and currently has the Gold Star. That's what I have most of my customers running (currently 7.0.2 or 7.0.3), where possible (considering hardware support, interoperability factors etc.).

7.1 would be a "Short Term Release". 7.2 is a "Long Term Release" but I've been holding off it it for production until a 7.2.1 release is issued. No bad experience in the lab, it's just good (in my opinion) to play it safe unless you really need features exclusive to 7.2.

 

@Marvin Rhoads

I take the chance to ask if you and possibly others have positive feedbacks on 7.0.3

Does it worth to go for it instead of 7.0.2 then 7.0.2.1?

Marvin Rhoads
Hall of Fame
Hall of Fame

If you are upgrading to 7.x then I would generally recommend going straight to 7.0.3 as of now. 7.1 or 7.2 are only indicated if you require a feature unique to one of those release trains.

If you are already on 7.0.1 or 7.0.2 then there little compelling reason to upgrade to 7.0.3 as it only fixes 4 additional published bugs vs. 7.0.2 (and two of them are cloud-specific).

https://www.cisco.com/c/en/us/td/docs/security/firepower/70/relnotes/firepower-release-notes-700/bugs.html#Cisco_Reference.dita_bb2b4dac-c7d8-4a43-b188-041e3aa2f6df

 

Deployment is currently at 6.7.0.3 and planning to go to 7.0.x, but:

7.0.1 is the current suggested release, but it has several security bugs, as well as one relevant bug to us CSCvz00934

7.0.2 has CSCwb93932 and needs a double upgrade to 7.0.2.1

7.0.3 is quite new and less tested than the others

That's why I needed some feedbacks

Marvin Rhoads
Hall of Fame
Hall of Fame

While 7.0.3 is less-widely deployed as of today, it only adds bug fixes on top of 7.0.2 so it is pretty low risk.

Review Cisco Networking for a $25 gift card