Firepower FMC HA

Requirements:

both management peers require identical software versions, capacity/hardware models, and separate licenses. They must be running the exact same Intrusion Rule Updates, Vulnerability Database (VDB), and Lightweight Security Packages.

Can't create HA between FMC for AWS and FMC for VMware.


 1. Configuration

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/221089-configure-high-availability-on-fmc.html


2. Upgrade

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/220602-upgrade-fmc-in-high-availability.html


3. Troubleshooting

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/222495-troubleshoot-for-fmc-ha.html


On FTD with HA FMC:

> show managers
Type                      : Manager
Host                      : 192.168.100.41
Display name              : 192.168.100.41
Version                   : 7.4.3 (Build 315)
Identifier                : e14cfec8-d542-11f0-acf5-b9807ef5d1c1
Registration              : Completed
Management type           : Configuration and analytics

Type                      : Manager
Host                      : 192.168.100.42
Display name              : 192.168.100.42
Version                   : 7.4.3 (Build 315)
Identifier                : 86ef50fe-d545-11f0-bf93-84dce0dcf86f
Registration              : Completed
Management type           : Configuration and analytics


>


Break HA



After break HA, both FMCs will be in standalone mode, only this FMC has registered devices, peer has no registered devices.













Comments