4 Comments

  1. Mark Field
    July 23, 2018 @ 11:31 am

    I wish this had worked because I have FTD’s in China that i can’t deploy to but ccm.properties does not exist in that directory so not sure how the deploy process would use those parameters.

    Reply

    • lammle
      July 25, 2018 @ 5:42 pm

      have no idea what you are asking me, sorry.

      Reply

  2. George
    August 30, 2019 @ 5:29 pm

    Hi Todd..

    Talking about bandwidth. Is there any information on how much traffic or bandwidth does a Managed Device (ASA with Firepower module) will send to FMC to log all the security events? I know this will depend on the network size, number of users, etc… but is there any formula to calculate that bandwidth consumption? The thing is that the managed device (sensor) is located in a branch office connected via MPLS link. There is a question similar to this one here: https://community.cisco.com/t5/firepower/firepower-sensor-distribute-deployment/td-p/3298522

    Somebody said:
    Bandwidth up from sensor to the managing FMC can vary greatly. Event reporting will consume, on average, 700 bytes/event. So that’s 5600 bits x your anticipated number of events per second (EPS).

    thanks!

    Reply

    • Todd Lammle
      August 30, 2019 @ 5:34 pm

      it will greatly on your configuration for logging in the ACP rules….the highest FMC can only take 20,000 EPS…so you need to think about that when transferring packets from the device (it will transfer all snort event packets by default, which is good), as well as logging on the ACP configuration.

      Reply

Leave a Reply

Your email address will not be published. Required fields are marked *