06-30-2022 06:33 AM
Can someone elaborate more on the FTDv tier vs non tier. Is the Tiered layer used strictly for use in the public cloud? Azure, AWS etc.
And the non-tiered designed for on prem use? If the non-tiered can be deployed in KVM/ESXi is the virtual appliance for users who do not have an active esxi/kvm hypervisor?
06-30-2022 09:26 AM
check the below :
the new tiered one is the latest feature from 7.0 onwards.
https://blogs.cisco.com/security/secure-and-save-with-cisco-secure-firewall-threat-defense-virtual
07-01-2022 07:43 AM
Understood about tiering moving forward. But, I wanted to know if we purchase the tiered option, do we need to purchase the virtual appliance? What does the virtual appliance get me over the tiered FTDv20 for example? Is the virtual appliance the same as FTDv100?
07-01-2022 08:46 AM - edited 07-01-2022 08:46 AM
if you using Cloud service - they are offering tier License with market place on AWS.
or you doing BYOD ?
07-01-2022 08:56 AM
I'm not sure. Its for a customer. So, my understanding is tiered is only available for cloud deployments. If you want to quote the non-tiered its suggested to quote the non-tiered with the virtual appliance?
If were quoting the tiered then there is no reason to quote the virtual appliance?
07-01-2022 08:57 AM
The traditional FTDv appliances with the traditional licenses support three sets of CPUv and RAM:
4xCPUv / 8GB RAM
8xCPUv / 16GB RAM
12xCPUv / 24GB RAM
However, with the new licensing model you can increase those resources up to support 16xCPUv and 32GB of RAM. This new model is very similar to what Palo Alto does with the virtual firewalls licenses such as PA VM-50, VM-100 and so on, each VM tier has to be allocated resources within a specific amount of CPUv and RAM. It is also similar to the old way of deploying ISE VM nodes, small, medium, and large licenses.
With the new FTDv licensing model you buy what you need, and when you deploy the FTDv and select the right tier bundle from the FMC, the tier will then be checked against your smart account to lookup the licenses available. If you deploy the new tier with a higher bundle than the licenses you have on the smart account, that will trigger a mismatch between the allocated and the allowed resources.
07-01-2022 09:57 AM
Thanks. All of this makes sense. I guess what I’m asking if all the tiered firewalls are options why do would you need to quote the virtual firewall appliance sku listed in the above doc?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide