cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1475
Views
0
Helpful
6
Replies

FTDv Confusion

bouwman22
Level 1
Level 1

Can someone elaborate more on the FTDv tier vs non tier. Is the Tiered layer used strictly for use in the public cloud? Azure, AWS etc.

 

 

 

 

And the non-tiered designed for on prem use? If the non-tiered can be deployed in KVM/ESXi is the virtual appliance for users who do not have an active esxi/kvm hypervisor?

6 Replies 6

balaji.bandi
Hall of Fame
Hall of Fame

check the below :

the new tiered one is the latest feature from 7.0 onwards.

 

https://blogs.cisco.com/security/secure-and-save-with-cisco-secure-firewall-threat-defense-virtual

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

bouwman22
Level 1
Level 1

Understood about tiering moving forward. But, I wanted to know if we purchase the tiered option, do we need to purchase the virtual appliance?  What does the virtual appliance get me over the tiered FTDv20 for example? Is the virtual appliance the same as FTDv100?

if you using Cloud service - they are offering tier License with market place on AWS.

 

or you doing BYOD ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

bouwman22
Level 1
Level 1

I'm not sure. Its for a customer. So, my understanding is tiered is only available for cloud deployments. If you want to quote the non-tiered its suggested to quote the non-tiered with the virtual appliance?

If were quoting the tiered then there is no reason to quote the virtual appliance?

The traditional FTDv appliances with the traditional licenses support three sets of CPUv and RAM:

4xCPUv / 8GB RAM

8xCPUv / 16GB RAM

12xCPUv / 24GB RAM

However, with the new licensing model you can increase those resources up to support 16xCPUv and 32GB of RAM. This new model is very similar to what Palo Alto does with the virtual firewalls licenses such as PA VM-50, VM-100 and so on, each VM tier has to be allocated resources within a specific amount of CPUv and RAM. It is also similar to the old way of deploying ISE VM nodes, small, medium, and large licenses.

With the new FTDv licensing model you buy what you need, and when you deploy the FTDv and select the right tier bundle from the FMC, the tier will then be checked against your smart account to lookup the licenses available. If you deploy the new tier with a higher bundle  than the licenses you have on the smart account, that will trigger a mismatch between the allocated and the allowed resources.

Thanks. All of this makes sense. I guess what I’m asking if all the tiered firewalls are options why do would you need to quote the virtual firewall appliance sku  listed in the above doc?