Overview
Consider these guidelines and limitations for deploying Management Center Virtual on AWS. Understand supported features, prerequisites, interface and licensing requirements, and platform constraints so you can plan a compliant and functional deployment. Learn about restrictions related to networking, instance configuration, high availability, and unsupported capabilities.
Supported Features (7.1.0+)
-
Management Center Virtual 300 (FMCv300) for AWS—A new scaled Firewall Management Center Virtual image is available on the AWS platform that supports managing up to 300 devices and has higher disk capacity.
-
Firewall Management Center Virtual high availability (HA) is supported.
Prerequisites
The following prerequisites pertain to the Firewall Management Center Virtual on AWS:
-
An Amazon account. You can create one at aws.amazon.com.
-
A Cisco Smart Account. You can create one at Cisco Software Central (https://software.cisco.com/).
-
License the Firewall Management Center Virtual. See Firewall Management Center Virtual Licenses for general guidelines about virtual platform licenses; see “Licensing the System” in the Secure Firewall Management Center Configuration Guide for more detailed information about how to manage licenses.
-
The Firewall Management Center Virtual interface requirements:
-
Management interface.
-
-
Communication Paths:
-
Public/elastic IPs for access into the Firewall Management Center Virtual.
-
-
For the Firewall Management Center Virtual and System compatibility, see the Cisco Secure Firewall Threat Defense Compatibility Guide.
Guidelines
The following guidelines pertain to the Firewall Management Center Virtual on AWS:
-
Deployment in the Virtual Private Cloud (VPC).
-
Enhanced networking (SR-IOV) where available.
-
Deployment from Amazon Marketplace.
-
Maximum of four vCPUs per instance.
-
User deployment of L3 networks.
-
IPv6 is supported.
Limitations
The following limitations pertain to the Firewall Management Center Virtual on AWS:
-
The Firewall Management Center Virtual appliances do not have serial numbers. The page will show either None or Not Specified depending on the virtual platform.
-
Any IP address configuration (either from CLI or Firewall Management Center) must match what is created in the AWS console; you should note your configurations during deployment.
-
You cannot add interfaces after boot.
-
Cloning/snapshots are currently not supported.
-
Transport Layer Security (TLS) Server Identity Discovery is not supported with Geneve single-arm setup on AWS.