Professional Documents
Culture Documents
FireMon Architecture Reference-KB (Eric Updated)
FireMon Architecture Reference-KB (Eric Updated)
&
Supported Deployment Models
Sep 2020
• On Builds with over 500 devices, the DB machine should be the FM1100
Backup Solutions
• All options presented, should have some backup located outside of the FireMon
environment.
• Development recommends an SCP/SFTP server to house these backups. This
can be any Linux box with space and the ability to create a username and
directory permissions.
• Ensuring the SCP/SFTP server can communicate with all servers is ideal as it
lets you quickly move backups and reduces downtime.
1 1 VM/appliance containing AS,DB,DC roles Recommended only for smaller deployments (< 20 FWs)
2 1 VM/appliance with AS + DB roles Usual mode of deployment for customers in APAC. Where
1 or more VMs/appliances with DC role possible, DC should be separate from AS+DB, even for smaller
deployments
3 1 VM/appliance with AS + DB roles Cold standby option, offers some form of redundancy without
1 VM/appliance with AS + DB roles (cold standby) committing too much resources
1 or more VMs/appliances with DC role
4 1 VM/appliance with AS role For bigger deployments (>150 FWs)
1 VM/appliance with DB role
1 or more VMs/appliances with DC role
DC Machine Requirements
AS/DB01 AS/DB01
DB Machine DB Machine •
ecosystem
Elastic search shards between the DB’s. The closed
DB Machine answers the request
• NFSv4 is the only known supported version.
• This Setup requires the client be able to create
users on the NFS with specific names/ids and grant
the FireMon “root” user full permissions
DB01 DR_DB01
Requirements
AS Machine
DB Machine Cluster • AS Machine Redundancy
• Same subnet for AS Machines
• DC Machines talk to VIP LB Address
• AS to DB communication based on DB FQDN
• AS to DB connectivity does not utilize LB
• LB needs to support websockets at L7 LB mode
• Persistence needed initially for ecosystem join
DB01 AS01
AS02
DC Machine
F5 Server
f5
VIP DC01
DB01 DR_DB01