Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, is the centralized administrative and policy platform for Cisco Secure Firewall Threat Defense, Cisco Secure IPS, Cisco Firepower Threat Defense for ISR, and Cisco Malware Defense. It consolidates firewall administration, application control, intrusion prevention, URL filtering, advanced malware protection, event correlation, reporting, network discovery, and response automation into one management system.
The platform is available as a physical appliance, virtual appliance, cloud-delivered service, or service-consumed deployment. Physical appliance selection is based on the number of sensors, network map size, IPS event volume, event rate, and local event-retention requirements.
Product role and management scope
FMC provides centralized policy and operational control for distributed Cisco security deployments. A single management platform can administer multiple security functions and apply consistent policy across multiple security solutions.
The principal management functions are:
- Firewall access policy
- Application visibility and control
- Intrusion prevention
- URL filtering
- Advanced malware protection
- Network discovery
- Threat intelligence integration
- Event correlation and prioritization
- Device health monitoring
- Reporting and dashboards
- Role-based administration
- Automated security response
- Security event export and third-party integration
FMC supports both physical and virtual Cisco Secure Firewall Threat Defense deployments. It also manages Cisco Secure IPS, Cisco Firepower Threat Defense for ISR, and Cisco Malware Defense.
The management model is policy-centric. Firewall access, application control, threat prevention, URL filtering, and advanced malware protection settings can be configured within a single policy framework and deployed to multiple security solutions. This reduces duplicated administration and helps maintain consistent controls across sites.
Visibility, discovery, and event operations
FMC performs passive network analysis to discover users, applications, and devices. The resulting context helps security teams assess the potential impact of an attack against specific systems rather than evaluating an event only by its signature or source address.
Network Discovery supports:
- Identification of users and applications
- Discovery of network devices and hosts
- Contextual analysis of security events
- Tuning of intrusion prevention signature sets based on discovered systems
- Integration with third-party vulnerability management systems
The platform provides trend information, high-level statistics, event detail, compliance information, forensic data, workflow data, and real-time device health monitoring. Dashboards and reports can be customized, and event information is presented through tables, graphs, charts, and hyperlinks.
The maximum network map size is a sizing constraint. It represents the supported host and user mapping capacity and should be considered separately from sensor count and event rate. A deployment may have sufficient sensor capacity but still require a larger platform because of the number of tracked hosts, users, or event records.
FMC also supports correlation and prioritization of attack events with network vulnerabilities. This allows security teams to focus on events associated with exposed or vulnerable assets. Correlation can include network, endpoint, intrusion, and security intelligence sources.
Policy control and administrative separation
FMC supports separation of duties through role-based access control. Administrative personas such as NetOps and SecOps can be defined with granular permissions so that users receive only the access required for their responsibilities.
The platform supports up to 100 management domains. Each domain can maintain separate event data, reporting, and network mapping. Role-based access control is used to enforce administrative separation.
Policy inheritance provides a hierarchy in which lower-level policies inherit settings from higher-level policies. This is useful for environments that require common baseline controls with controlled site, tenant, or business-unit variations.
Presales assessment should identify whether the customer needs:
- Centralized policy across multiple firewalls
- Separate administrative domains
- Independent reporting by tenant or business unit
- Policy inheritance for common controls
- Restricted administrative access by operational role
- Centralized event and network mapping data
Multitenancy requirements should be established before model selection because event volume and network map size apply to the selected FMC platform.
Identity, dynamic workloads, and automated response
FMC supports Azure AD-based user and group access policy control through integration with Cisco Identity Services Engine. It can use Cisco ISE security group tags, device type, location IP, and related identity context for access control and rapid threat containment.
Automatic Security Response can correlate security events and trigger actions through:
- Syslog
- SNMP
- Remediation modules
FMC also includes Cisco Secure Dynamic Attribute Connector functionality. The connector provides programmatic policy management for environments in which IP addresses and workloads change frequently. It can create dynamic objects from workload tags and external service data.
Supported dynamic object sources include:
- AWS
- Azure
- Google Cloud Platform
- VMware
- Office 365
- GitHub
- Azure Service Tags
- Zoom
- Webex
- Generic text files containing IP prefixes
This capability is relevant for cloud and virtualization environments in which security policy cannot depend exclusively on static address objects. Presales discovery should determine whether workload tags, SaaS service ranges, known IP lists, or vulnerable IP lists must be reflected in policy automatically.
Threat intelligence, application control, and integrations
FMC integrates with Cisco Talos security, threat, and vulnerability intelligence. It supports both IP-based and URL-based security intelligence and can ingest third-party threat feeds and threat intelligence platforms using STIX, TAXII, or flat file formats.
Application visibility and control supports detailed identification of thousands of commercial applications. The platform also uses the open-source Open App ID standard for identification and control of custom applications.
Cisco Security Analytics and Logging integration provides centralized firewall log management, behavioral analysis, real-time threat detection, and continuous analysis of security posture.
Cisco Secure Workload integration provides visibility and policy enforcement for distributed and dynamic applications across network and workload environments.
Open APIs support integration with external systems for:
- Exporting FMC event data to SIEM platforms
- Enriching Cisco IPS data with third-party vulnerability information
- Triggering workflows and remediation
- Querying the FMC database for reporting and analytics
- Integrating with Cisco Secure Malware Analytics
- Integrating with Cisco ISE
- Integrating with Cisco Umbrella
- Initiating network access control or endpoint quarantine workflows
SecureX integration provides a ribbon within FMC for pivoting into threat investigation, orchestration, and remediation workflows. SecureX threat response can query sightings for indicators such as IP addresses and correlate threat intelligence from Cisco Talos and third-party sources. SecureX Orchestrator can invoke FMC API calls for routine administrative tasks.
Physical appliance selection
The physical appliance family listed in the platform specifications consists of FMC 1700, FMC 2700, and FMC 4700. All three models provide the same management capabilities. They differ in scale, memory, processor, storage, event capacity, sensor count, and network interface capability.
Physical appliance comparison
| Model | Maximum sensors | Maximum IPS events | Event rate | Network map hosts/users | Memory | Event storage | CPU | Best For |
|---|---|---|---|---|---|---|---|---|
| FMC 1700 | 50 | 30 million | 5,000 eps | 50,000 / 50,000 | 32 GB | 900 GB | AMD 1P Rome 7232P | Small and mid-sized deployments with up to 50 managed sensors |
| FMC 2700 | 300 | 60 million | 12,000 eps | 150,000 / 150,000 | 64 GB | 1.8 TB | AMD 1P Rome 7282 | Larger distributed environments requiring up to 300 sensors |
| FMC 4700 | 1,000 | 400 million | 30,000 eps | 600,000 / 600,000 | 128 GB | 3.2 TB | AMD 1P Rome 7352 | Large enterprise and service-provider-scale deployments |
The management interface consists of two built-in 10GbE RJ45 OCP 3.0 NICs supporting 100 Mbps, 1 Gbps, and 10 Gbps. The primary management port is eth0. eth1, eth2, and eth3 can be used as secondary management or event ports.
All physical models include:
- Two USB 3.0 Type A ports
- One VGA port using a three-row 15-pin DB-15 connector
- Two fixed SFP+ ports
- Secure boot
- High-availability support
- Two 1050 W AC power supplies
- Hot-swappable, redundant 1+1 power configuration
- Front-to-back airflow
- 1RU form factor
Supported SFP options vary by model. The FMC 1700 and FMC 2700 support SFP-10G-SR and SFP-10G-LR. The FMC 4700 additionally supports SFP-25G-SR-S, SFP-10/25G-LR-S, and SFP-10/25G-CSR-S.
The physical models use internal RDIMMs that are not field replaceable. The FMC 1700 uses two 16 GB DDR4-3200 MHz DIMMs. The FMC 2700 uses four 16 GB DIMMs, and the FMC 4700 uses eight 16 GB DIMMs.
Storage is model-specific:
- FMC 1700: two 1.2 TB 10K SAS hard disk drives in RAID 1
- FMC 2700: four 600 GB 10K SAS hard disk drives in RAID 5
- FMC 4700: ten 1.2 TB 10K SAS hard disk drives in RAID 6
The drives are hot swappable. Each chassis has a dedicated internal riser for a PCIe-style Cisco modular RAID controller. The RAID controller is an internal component and is not field replaceable.
Virtual appliance and cloud options
FMC Virtual supports multiple hypervisors and cloud platforms. All FMC Virtual models require 28 GB of RAM, with 32 GB recommended. An additional 2 vCPUs and 2 GB of RAM are recommended when running the Secure Dynamic Attribute Connector.
FMC Virtual comparison
| Model | Maximum sensors | Maximum IPS events | Memory | CPU | Event storage | Network map | Event rate | Best For |
|---|---|---|---|---|---|---|---|---|
| FMCv2 | 2 | 10 million | 32 GB | 8/4 vCPUs | 250 GB | 50,000 / 50,000 | Varies | Very small virtual deployments |
| FMCv10 | 10 | 10 million | 32 GB | 8/4 vCPUs | 250 GB | 50,000 / 50,000 | Varies | Small virtual deployments |
| FMCv25 | 25 | 10 million | 32 GB | 8/4 vCPUs | 250 GB | 50,000 / 50,000 | Varies | Small distributed environments |
| FMCv300 | 300 | 60 million | 64 GB | 32 vCPUs | 2.2 TB | 150,000 / 150,000 | 12,000 eps | Large virtual deployments |
FMCv2, FMCv10, and FMCv25 support VMware, KVM, AWS, Azure, GCP, OCI, Nutanix, Hyperflex, and OpenStack. FMCv300 supports VMware, AWS, and OCI.
High availability is supported for FMCv10 and FMCv25 on VMware, AWS, and OCI. High availability is not supported on FMCv2. FMCv300 supports high availability on VMware, AWS, and OCI.
The listed hypervisor and cloud configurations include:
| Platform | Supported configuration |
|---|---|
| VMware vSphere | ESXi Server 5.1, 5.5, 6.0, 6.5, 6.7, and 7.0; vCenter Server optional |
| KVM | Ubuntu 18.04 LTS and Red Hat Enterprise Linux version 7.1 |
| AWS | c3.4xlarge, c4.4xlarge, or c5.4xlarge; 16 vCPUs and 30 to 32 GB RAM |
| Microsoft Azure | Standard_D4_v2; 8 vCPUs and 28 GB RAM |
| GCP | c2-standard-8 with 8 vCPUs and 32 GB RAM; c2-standard-16 with 16 vCPUs and 64 GB RAM |
| OCI | VM.Standard 2.4 with 60 GB RAM |
| Nutanix | Nutanix AHV |
| Hyperflex | 4 to 8 vCPUs and 28 to 32 GB for FMCv-2, FMCv-10, and FMCv-25; 32 vCPUs and 64 GB for FMCv-300 |
Cloud-delivered FMC through CDO removes the requirement to manage FMC software updates directly. Cloud sizing and compatibility depend on the supported cloud-delivered service configuration.
Physical and environmental specifications
All physical models are 1RU and use the same published chassis dimensions:
- Depth: 30 inches
- Width: 16.9 inches
- Height: 1.7 inches
- Metric dimensions: 76.2 x 42.9 x 4.3 cm
- Airflow: Front to back
- Operating temperature: 50 F to 95 F, or 10 C to 35 C
- Maximum power rating: 1,050 W
- Power input: 100 to 240 VAC nominal
- Input range: 90 to 264 VAC
- Maximum current: 9.2 amps at 100 VAC and 5.2 amps at 230 VAC
- Power consumption rating: 2,626 BTU/hr
Shipping weight is model-specific:
| Model | Shipping weight |
|---|---|
| FMC 1700 | 32.2 lb, 16.6 kg |
| FMC 2700 | 34.1 lb, 16.8 kg |
| FMC 4700 | 36 lb, 17.0 kg |
MTBF is not specified in the platform specifications. Acoustic noise is also not specified. Rack, data-center, and facilities planning should therefore use the published dimensions, airflow direction, power requirements, and operating temperature range, while obtaining any required MTBF or acoustic data through the applicable hardware documentation or ordering process.
Presales sizing rules
Use the following order when sizing FMC:
- Count all physical and virtual sensors that FMC must manage.
- Estimate the maximum IPS event volume retained and processed.
- Estimate sustained and burst event rate in events per second.
- Count hosts and users that must be represented in the network map.
- Determine required local event storage.
- Confirm high-availability requirements.
- Confirm whether management, event, or secondary interfaces require separate connectivity.
- Validate rack power, airflow, temperature, and redundant power availability.
- Confirm whether the deployment is physical, virtual, cloud-delivered, or service-consumed.
- Add capacity for expected growth rather than selecting only against the current sensor count.
The selected model must satisfy all relevant limits, not only the sensor count. For example, an environment below the maximum sensor count may still require a larger model because of event rate, network map size, IPS event volume, or storage requirements.
Use FMC 1700 when the deployment fits within 50 sensors, 5,000 events per second, 30 million IPS events, and a 50,000-host and 50,000-user network map. Use FMC 2700 when the environment requires up to 300 sensors, 12,000 events per second, 60 million IPS events, or a 150,000-host and 150,000-user map. Use FMC 4700 for environments requiring up to 1,000 sensors, 30,000 events per second, 400 million IPS events, or a 600,000-host and 600,000-user map.
For virtual deployments, select the FMCv model based on sensor count, IPS event volume, storage, and cloud or hypervisor placement. Do not assume that the virtual appliance has the same event-rate characteristics as a physical model when the specification states that the rate varies.
Warranty and service
The datasheet directs customers to the Cisco Product Warranties resource for warranty information. The supplied platform specifications do not state warranty duration, replacement response time, software support entitlement, hardware replacement procedure, or service-level options.
Ordering and licensing information for physical appliances, virtual appliances, and cloud-delivered service is provided through the Cisco Network Security Ordering Guide. The model identifiers covered by the platform specifications are FMC 1700, FMC 2700, FMC 4700, FMCv2, FMCv10, FMCv25, and FMCv300.