Requirements:
both management peers require identical software versions, capacity/hardware models, and separate licenses. They must be running the exact same Intrusion Rule Updates, Vulnerability Database (VDB), and Lightweight Security Packages.
Can't create HA between FMC for AWS and FMC for VMware.
1. Configuration
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/221089-configure-high-availability-on-fmc.html
2. Upgrade
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/220602-upgrade-fmc-in-high-availability.html
3. Troubleshooting
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/222495-troubleshoot-for-fmc-ha.html
On FTD with HA FMC:
> show managers
Type : Manager
Host : 192.168.100.41
Display name : 192.168.100.41
Version : 7.4.3 (Build 315)
Identifier : e14cfec8-d542-11f0-acf5-b9807ef5d1c1
Registration : Completed
Management type : Configuration and analytics
Type : Manager
Host : 192.168.100.41
Display name : 192.168.100.41
Version : 7.4.3 (Build 315)
Identifier : e14cfec8-d542-11f0-acf5-b9807ef5d1c1
Registration : Completed
Management type : Configuration and analytics
Type : Manager
Host : 192.168.100.42
Display name : 192.168.100.42
Version : 7.4.3 (Build 315)
Identifier : 86ef50fe-d545-11f0-bf93-84dce0dcf86f
Registration : Completed
Management type : Configuration and analytics
>
Break HA
After break HA, both FMCs will be in standalone mode, only this FMC has registered devices, peer has no registered devices.
Comments
Post a Comment