Cisco Secure Firewall Management Center Virtual Getting Started Guide

PDF

Guidelines and Limitations

Want to summarize with AI?

Log in

Overview

Consider these guidelines and limitations for deploying Management Center Virtual on Azure. Learn about the supported VM sizes, licensing requirements, shutdown procedures, and unsupported capabilities to avoid configuration issues. Use this information to plan a compliant deployment and operate the virtual appliance within platform constraints.

Supported Features

  • Supported Azure VM sizes:

    • Standard_D3_v2—4 vCPUs, 14GB memory, 250GB disk size

    • Standard_D4_v2—8 vCPUs, 28GB memory, 400GB disk size

Licensing

The Firewall Management Center Virtual in the Azure public marketplace supports the Bring Your Own License (BYOL) model. For the Firewall Management Center Virtual, this is a platform license rather than a feature license. The version of virtual license you purchase determines the number of devices you can manage via the Firewall Management Center Virtual. For example, you can purchase licenses that enable you to manage two devices, 10 devices, or 25 devices.

  • Licensing modes:

    • Smart License only

For licensing details, see Licensing the System in the Secure Firewall Management Center Configuration Guide for more information about how to manage licenses; see Cisco Secure Firewall Management Center Feature Licenses for an overview of feature licenses for the System, including helpful links.

System Shut Down and Restart

Do not use the Restart and Stop controls on the Azure Virtual machine overview page to power on the Firewall Management Center Virtual VM. These are not graceful shutdown mechanisms and can lead to database corruption.

Use the System > Configuration options available from the Firewall Management Center Virtual's Web interface to shut down or restart the virtual appliance.

Use the shutdown and restart commands from the Firewall Management Center Virtual's command line interface to shut down or restart the appliance.

Unsupported Features

  • Licensing modes:

    • Pay As You Go (PAYG) licensing.

    • Permanent License Reservation (PLR).

  • Management

    • Azure portal “reset password” function.

    • Console-based password recovery; because the user does not have real-time access to the console, password recovery is not possible. It is not possible to boot the password recovery image. The only recourse is to deploy a new Firewall Management Center Virtual VM.

  • VM import/export

  • HA is not supported on Secure Firewall version 7.4.1 and earlier versions.

  • Gen 2 VM generation on Azure

  • Re-sizing the VM after deployment

  • Migration or update of the Azure Storage SKU for the OS Disk of the VM from premium to standard SKU and vice versa