Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, is the centralized administrative and policy platform for Cisco Secure Firewall Threat Defense, Cisco Secure IPS, Cisco Firepower Threat Defense for ISR, and Cisco Malware Defense. It consolidates firewall administration, application control, intrusion prevention, URL filtering, advanced malware protection, event correlation, reporting, network discovery, and response automation into one management system.

The platform is available as a physical appliance, virtual appliance, cloud-delivered service, or service-consumed deployment. Physical appliance selection is based on the number of sensors, network map size, IPS event volume, event rate, and local event-retention requirements.

Product role and management scope

FMC provides centralized policy and operational control for distributed Cisco security deployments. A single management platform can administer multiple security functions and apply consistent policy across multiple security solutions.

The principal management functions are:

  • Firewall access policy
  • Application visibility and control
  • Intrusion prevention
  • URL filtering
  • Advanced malware protection
  • Network discovery
  • Threat intelligence integration
  • Event correlation and prioritization
  • Device health monitoring
  • Reporting and dashboards
  • Role-based administration
  • Automated security response
  • Security event export and third-party integration

FMC supports both physical and virtual Cisco Secure Firewall Threat Defense deployments. It also manages Cisco Secure IPS, Cisco Firepower Threat Defense for ISR, and Cisco Malware Defense.

The management model is policy-centric. Firewall access, application control, threat prevention, URL filtering, and advanced malware protection settings can be configured within a single policy framework and deployed to multiple security solutions. This reduces duplicated administration and helps maintain consistent controls across sites.

Visibility, discovery, and event operations

FMC performs passive network analysis to discover users, applications, and devices. The resulting context helps security teams assess the potential impact of an attack against specific systems rather than evaluating an event only by its signature or source address.

Network Discovery supports:

  • Identification of users and applications
  • Discovery of network devices and hosts
  • Contextual analysis of security events
  • Tuning of intrusion prevention signature sets based on discovered systems
  • Integration with third-party vulnerability management systems

The platform provides trend information, high-level statistics, event detail, compliance information, forensic data, workflow data, and real-time device health monitoring. Dashboards and reports can be customized, and event information is presented through tables, graphs, charts, and hyperlinks.

The maximum network map size is a sizing constraint. It represents the supported host and user mapping capacity and should be considered separately from sensor count and event rate. A deployment may have sufficient sensor capacity but still require a larger platform because of the number of tracked hosts, users, or event records.

FMC also supports correlation and prioritization of attack events with network vulnerabilities. This allows security teams to focus on events associated with exposed or vulnerable assets. Correlation can include network, endpoint, intrusion, and security intelligence sources.

Policy control and administrative separation

FMC supports separation of duties through role-based access control. Administrative personas such as NetOps and SecOps can be defined with granular permissions so that users receive only the access required for their responsibilities.

The platform supports up to 100 management domains. Each domain can maintain separate event data, reporting, and network mapping. Role-based access control is used to enforce administrative separation.

Policy inheritance provides a hierarchy in which lower-level policies inherit settings from higher-level policies. This is useful for environments that require common baseline controls with controlled site, tenant, or business-unit variations.

Presales assessment should identify whether the customer needs:

  • Centralized policy across multiple firewalls
  • Separate administrative domains
  • Independent reporting by tenant or business unit
  • Policy inheritance for common controls
  • Restricted administrative access by operational role
  • Centralized event and network mapping data

Multitenancy requirements should be established before model selection because event volume and network map size apply to the selected FMC platform.

Identity, dynamic workloads, and automated response

FMC supports Azure AD-based user and group access policy control through integration with Cisco Identity Services Engine. It can use Cisco ISE security group tags, device type, location IP, and related identity context for access control and rapid threat containment.

Automatic Security Response can correlate security events and trigger actions through:

  • Email
  • Syslog
  • SNMP
  • Remediation modules

FMC also includes Cisco Secure Dynamic Attribute Connector functionality. The connector provides programmatic policy management for environments in which IP addresses and workloads change frequently. It can create dynamic objects from workload tags and external service data.

Supported dynamic object sources include:

  • AWS
  • Azure
  • Google Cloud Platform
  • VMware
  • Office 365
  • GitHub
  • Azure Service Tags
  • Zoom
  • Webex
  • Generic text files containing IP prefixes

This capability is relevant for cloud and virtualization environments in which security policy cannot depend exclusively on static address objects. Presales discovery should determine whether workload tags, SaaS service ranges, known IP lists, or vulnerable IP lists must be reflected in policy automatically.

Threat intelligence, application control, and integrations

FMC integrates with Cisco Talos security, threat, and vulnerability intelligence. It supports both IP-based and URL-based security intelligence and can ingest third-party threat feeds and threat intelligence platforms using STIX, TAXII, or flat file formats.

Application visibility and control supports detailed identification of thousands of commercial applications. The platform also uses the open-source Open App ID standard for identification and control of custom applications.

Cisco Security Analytics and Logging integration provides centralized firewall log management, behavioral analysis, real-time threat detection, and continuous analysis of security posture.

Cisco Secure Workload integration provides visibility and policy enforcement for distributed and dynamic applications across network and workload environments.

Open APIs support integration with external systems for:

  • Exporting FMC event data to SIEM platforms
  • Enriching Cisco IPS data with third-party vulnerability information
  • Triggering workflows and remediation
  • Querying the FMC database for reporting and analytics
  • Integrating with Cisco Secure Malware Analytics
  • Integrating with Cisco ISE
  • Integrating with Cisco Umbrella
  • Initiating network access control or endpoint quarantine workflows

SecureX integration provides a ribbon within FMC for pivoting into threat investigation, orchestration, and remediation workflows. SecureX threat response can query sightings for indicators such as IP addresses and correlate threat intelligence from Cisco Talos and third-party sources. SecureX Orchestrator can invoke FMC API calls for routine administrative tasks.

Physical appliance selection

The physical appliance family listed in the platform specifications consists of FMC 1700, FMC 2700, and FMC 4700. All three models provide the same management capabilities. They differ in scale, memory, processor, storage, event capacity, sensor count, and network interface capability.

Physical appliance comparison

Model Maximum sensors Maximum IPS events Event rate Network map hosts/users Memory Event storage CPU Best For
FMC 1700 50 30 million 5,000 eps 50,000 / 50,000 32 GB 900 GB AMD 1P Rome 7232P Small and mid-sized deployments with up to 50 managed sensors
FMC 2700 300 60 million 12,000 eps 150,000 / 150,000 64 GB 1.8 TB AMD 1P Rome 7282 Larger distributed environments requiring up to 300 sensors
FMC 4700 1,000 400 million 30,000 eps 600,000 / 600,000 128 GB 3.2 TB AMD 1P Rome 7352 Large enterprise and service-provider-scale deployments

The management interface consists of two built-in 10GbE RJ45 OCP 3.0 NICs supporting 100 Mbps, 1 Gbps, and 10 Gbps. The primary management port is eth0. eth1, eth2, and eth3 can be used as secondary management or event ports.

All physical models include:

  • Two USB 3.0 Type A ports
  • One VGA port using a three-row 15-pin DB-15 connector
  • Two fixed SFP+ ports
  • Secure boot
  • High-availability support
  • Two 1050 W AC power supplies
  • Hot-swappable, redundant 1+1 power configuration
  • Front-to-back airflow
  • 1RU form factor

Supported SFP options vary by model. The FMC 1700 and FMC 2700 support SFP-10G-SR and SFP-10G-LR. The FMC 4700 additionally supports SFP-25G-SR-S, SFP-10/25G-LR-S, and SFP-10/25G-CSR-S.

The physical models use internal RDIMMs that are not field replaceable. The FMC 1700 uses two 16 GB DDR4-3200 MHz DIMMs. The FMC 2700 uses four 16 GB DIMMs, and the FMC 4700 uses eight 16 GB DIMMs.

Storage is model-specific:

  • FMC 1700: two 1.2 TB 10K SAS hard disk drives in RAID 1
  • FMC 2700: four 600 GB 10K SAS hard disk drives in RAID 5
  • FMC 4700: ten 1.2 TB 10K SAS hard disk drives in RAID 6

The drives are hot swappable. Each chassis has a dedicated internal riser for a PCIe-style Cisco modular RAID controller. The RAID controller is an internal component and is not field replaceable.

Virtual appliance and cloud options

FMC Virtual supports multiple hypervisors and cloud platforms. All FMC Virtual models require 28 GB of RAM, with 32 GB recommended. An additional 2 vCPUs and 2 GB of RAM are recommended when running the Secure Dynamic Attribute Connector.

FMC Virtual comparison

Model Maximum sensors Maximum IPS events Memory CPU Event storage Network map Event rate Best For
FMCv2 2 10 million 32 GB 8/4 vCPUs 250 GB 50,000 / 50,000 Varies Very small virtual deployments
FMCv10 10 10 million 32 GB 8/4 vCPUs 250 GB 50,000 / 50,000 Varies Small virtual deployments
FMCv25 25 10 million 32 GB 8/4 vCPUs 250 GB 50,000 / 50,000 Varies Small distributed environments
FMCv300 300 60 million 64 GB 32 vCPUs 2.2 TB 150,000 / 150,000 12,000 eps Large virtual deployments

FMCv2, FMCv10, and FMCv25 support VMware, KVM, AWS, Azure, GCP, OCI, Nutanix, Hyperflex, and OpenStack. FMCv300 supports VMware, AWS, and OCI.

High availability is supported for FMCv10 and FMCv25 on VMware, AWS, and OCI. High availability is not supported on FMCv2. FMCv300 supports high availability on VMware, AWS, and OCI.

The listed hypervisor and cloud configurations include:

Platform Supported configuration
VMware vSphere ESXi Server 5.1, 5.5, 6.0, 6.5, 6.7, and 7.0; vCenter Server optional
KVM Ubuntu 18.04 LTS and Red Hat Enterprise Linux version 7.1
AWS c3.4xlarge, c4.4xlarge, or c5.4xlarge; 16 vCPUs and 30 to 32 GB RAM
Microsoft Azure Standard_D4_v2; 8 vCPUs and 28 GB RAM
GCP c2-standard-8 with 8 vCPUs and 32 GB RAM; c2-standard-16 with 16 vCPUs and 64 GB RAM
OCI VM.Standard 2.4 with 60 GB RAM
Nutanix Nutanix AHV
Hyperflex 4 to 8 vCPUs and 28 to 32 GB for FMCv-2, FMCv-10, and FMCv-25; 32 vCPUs and 64 GB for FMCv-300

Cloud-delivered FMC through CDO removes the requirement to manage FMC software updates directly. Cloud sizing and compatibility depend on the supported cloud-delivered service configuration.

Physical and environmental specifications

All physical models are 1RU and use the same published chassis dimensions:

  • Depth: 30 inches
  • Width: 16.9 inches
  • Height: 1.7 inches
  • Metric dimensions: 76.2 x 42.9 x 4.3 cm
  • Airflow: Front to back
  • Operating temperature: 50 F to 95 F, or 10 C to 35 C
  • Maximum power rating: 1,050 W
  • Power input: 100 to 240 VAC nominal
  • Input range: 90 to 264 VAC
  • Maximum current: 9.2 amps at 100 VAC and 5.2 amps at 230 VAC
  • Power consumption rating: 2,626 BTU/hr

Shipping weight is model-specific:

Model Shipping weight
FMC 1700 32.2 lb, 16.6 kg
FMC 2700 34.1 lb, 16.8 kg
FMC 4700 36 lb, 17.0 kg

MTBF is not specified in the platform specifications. Acoustic noise is also not specified. Rack, data-center, and facilities planning should therefore use the published dimensions, airflow direction, power requirements, and operating temperature range, while obtaining any required MTBF or acoustic data through the applicable hardware documentation or ordering process.

Presales sizing rules

Use the following order when sizing FMC:

  1. Count all physical and virtual sensors that FMC must manage.
  2. Estimate the maximum IPS event volume retained and processed.
  3. Estimate sustained and burst event rate in events per second.
  4. Count hosts and users that must be represented in the network map.
  5. Determine required local event storage.
  6. Confirm high-availability requirements.
  7. Confirm whether management, event, or secondary interfaces require separate connectivity.
  8. Validate rack power, airflow, temperature, and redundant power availability.
  9. Confirm whether the deployment is physical, virtual, cloud-delivered, or service-consumed.
  10. Add capacity for expected growth rather than selecting only against the current sensor count.

The selected model must satisfy all relevant limits, not only the sensor count. For example, an environment below the maximum sensor count may still require a larger model because of event rate, network map size, IPS event volume, or storage requirements.

Use FMC 1700 when the deployment fits within 50 sensors, 5,000 events per second, 30 million IPS events, and a 50,000-host and 50,000-user network map. Use FMC 2700 when the environment requires up to 300 sensors, 12,000 events per second, 60 million IPS events, or a 150,000-host and 150,000-user map. Use FMC 4700 for environments requiring up to 1,000 sensors, 30,000 events per second, 400 million IPS events, or a 600,000-host and 600,000-user map.

For virtual deployments, select the FMCv model based on sensor count, IPS event volume, storage, and cloud or hypervisor placement. Do not assume that the virtual appliance has the same event-rate characteristics as a physical model when the specification states that the rate varies.

Warranty and service

The datasheet directs customers to the Cisco Product Warranties resource for warranty information. The supplied platform specifications do not state warranty duration, replacement response time, software support entitlement, hardware replacement procedure, or service-level options.

Ordering and licensing information for physical appliances, virtual appliances, and cloud-delivered service is provided through the Cisco Network Security Ordering Guide. The model identifiers covered by the platform specifications are FMC 1700, FMC 2700, FMC 4700, FMCv2, FMCv10, FMCv25, and FMCv300.