Deploy the Firewall Management Center Virtual on Cisco Hyperflex
Cisco HyperFlex systems deliver hyperconvergence for any application, and anywhere. HyperFlex with Cisco Unified Computing System (Cisco UCS) technology that is managed through the Cisco Intersight cloud operations platform can power applications and data anywhere, optimize operations from a core datacenter to the edge and into public clouds, and therefore increase agility through accelerating DevOps practices.
You can deploy the Firewall Management Center Virtual on Cisco Hyperflex.
System Requirements
Firewall Management Center Virtual Requires 28 GB RAM
We recommend you do not decrease the default settings: 32 GB RAM for most the Firewall Management Center Virtual instances. To improve performance, you can always increase a virtual appliance’s memory and number of CPUs, depending on your available resources.Memory and Resource Requirements
-
You can deploy the Firewall Management Center Virtual using HyperFlex cluster provisioning hosted on HyperFlex ESX and ESXi hypervisors. See the Cisco Secure Firewall Threat Defense Compatibility Guide for hypervisor compatibility.
-
For the Firewall Management Center Virtual, check the latest Release Notes for details on whether a new release affects your environment. You may be required to increase resources to deploy the latest version.
-
The specific hardware used for the Firewall Management Center Virtual deployments can vary, depending on the number of instances deployed and usage requirements. Each virtual appliance you create requires a minimum resource allocation—memory, number of CPUs, and disk space—on the host machine.
-
The following table lists the recommended and default settings for the Firewall Management Center Virtual appliance.

Important
Be sure to allocate enough memory to ensure the optimal performance of your Firewall Management Center Virtual. If your Firewall Management Center Virtual has less than 32 GB memory, your system could experience policy deployment issues. Do not decrease the default settings, as they are the minimum required to run the system software.
|
Setting |
Minimum |
Default |
Recommended |
Adjustable Setting? |
|---|---|---|---|---|
|
Memory |
28 GB |
32 GB |
32 GB |
With restrictions. |
|
Virtual CPUs |
4 |
4 |
8 |
Yes, up to 8 |
|
Hard disk provisioned size |
250 GB |
250 GB |
n/a |
No, based on Disk Format selection |
|
Setting |
Default |
Adjustable Setting? |
|---|---|---|
|
Memory |
64 GB |
Yes |
|
Virtual CPUs |
32 |
No |
|
Hard disk provisioned size |
2.2 TB |
No, based on Disk Format selection |
For a list of supported platforms and specific hardware and operating system requirements, see the Compatibility Guide.
Guidelines and Limitations
Limitations
The following limitations exist when you deploy the Firewall Management Center Virtual for Cisco HyperFlex:
-
The Firewall Management Center Virtual appliances do not have serial numbers. The page shows either None or Not Specified depending on the virtual platform.
-
Cloning a virtual machine is not supported.
-
Restoring a virtual machine with snapshot is not supported.
-
VMware Workstation, Player, Server, and Fusion do not recognize OVF packaging and are not supported.
OVF File Guidelines
Virtual appliances use Open Virtual Format (OVF) packaging. You deploy a virtual appliance with a virtual infrastructure (VI) OVF template. The selection of the OVF file is based on the deployment target-
For deployment on vCenter—Cisco_Secure_FW_Mgmt_Center_Virtual_VMware-VI-X.X.X-xxx.ovf
where X.X.X-xxx is the version and build number of the System software you want to deploy. The installation process allows you to perform the entire initial setup for the Firewall Management Center Virtual appliance. You can specify:
-
A new password for the admin account.
-
Network settings that allow the appliance to communicate on your management network.
High Availability Support
You can establish high availability (HA) between two Firewall Management Center Virtual appliances deployed on Hyperflex host:
-
The two Firewall Management Center Virtual appliances in a high availability configuration must be the same model.
-
To establish the Firewall Management Center Virtual HA, Firewall Management Center Virtual requires an extra Firewall Management Center Virtual license entitlement for each the Firewall Threat Defense device that it manages in the HA configuration. However, the required Firewall Threat Defense feature license entitlement for each the Firewall Threat Defense device has no change regardless of the Firewall Management Center Virtual HA configuration. See License Requirements for Threat Defense Devices in a High Availability Pair in the Cisco Secure Firewall Management Center Device Configuration Guide for guidelines about licensing.
-
If you break the Firewall Management Center Virtual HA pair, the extra Firewall Management Center Virtual license entitlement is released, and you need only one entitlement for each the Firewall Threat Defense device.
See High Availability in the Cisco Secure Firewall Management Center Administration Guide for guidelines about high availability.
Related Documents
Release Notes for Cisco HX Data Platform
Configuration Guides for Cisco HX Data Platform
Cisco HyperFlex 4.0 for Virtual Server Infrastructure with VMware ESXi

Feedback