The Cisco Firepower Management Center (FMC) is the centralized administrative platform for Cisco Firepower security products, providing unified management of firewall access control, application visibility, intrusion prevention, URL filtering, advanced malware protection, event analysis, reporting, and device policy. It is available as a physical 1RU appliance or as a virtual appliance hosted on supported virtualization and cloud platforms.
Product role and supported security platforms
The FMC serves as the management and event-analysis point for:
- Cisco Firepower Next-Generation Firewall
- Cisco ASA with FirePOWER Services
- Cisco Firepower Next-Generation IPS
- Cisco FirePOWER Threat Defense for ISR
- Cisco Advanced Malware Protection
For ASA with FirePOWER Services, the FMC manages only the FirePOWER portion of the deployment.
The platform centralizes device, license, event, and policy management. It also supports role-based administration, customizable dashboards, reports, event correlation, remediation workflows, network behavior monitoring, and high-availability options on supported appliance models.
A key operational benefit is the ability to combine multiple security functions in a single policy framework. Firewall access, application control, threat prevention, URL filtering, and advanced malware protection settings can be administered through integrated policy workflows. A common policy can be deployed across multiple security solutions, helping reduce configuration variation and administrative errors.
Security visibility and operational capabilities
The FMC collects and correlates contextual information about users, applications, devices, operating systems, vulnerabilities, network services, malware, and threats. This information supports policy construction, event prioritization, incident investigation, and remediation.
The documented visibility categories include:
| Visibility category | FMC | Typical IPS | Typical NGFW |
|---|---|---|---|
| Threats | Yes | Yes | Yes |
| Users | Yes | Yes | Yes |
| Web applications | Yes | No | Yes |
| Application protocols | Yes | No | Yes |
| File transfers | Yes | No | Yes |
| Malware | Yes | No | No |
| Command-and-control servers | Yes | No | No |
| Client applications | Yes | No | No |
| Network servers | Yes | No | No |
| Operating systems | Yes | No | No |
| Routers and switches | Yes | No | No |
| Mobile devices | Yes | No | No |
| Printers | Yes | No | No |
| VoIP phones | Yes | No | No |
| Virtual machines | Yes | No | No |
| Vulnerability information | Yes | No | No |
The management workflow spans three operational phases:
- Before an attack: identify network resources, determine what requires protection, create firewall rules, and control more than 4000 commercial and custom applications.
- During an attack: apply intrusion prevention, URL reputation, and advanced malware protection policies; analyze files; and send selected files to an integrated sandbox when required.
- After an attack: display infected devices, create custom rules to stop attack progression, analyze malware, and support remediation.
The FMC also correlates attack events with network vulnerability information. This allows administrators to prioritize events that may have successfully affected vulnerable hosts rather than treating all alerts identically. Correlation can include network, endpoint, intrusion, and security intelligence data.
Policy, identity, and threat intelligence integration
Application visibility and control supports precise control over more than 4000 commercial applications. Open App ID can be used for detailed identification and control of custom applications.
Integration with Cisco Identity Services Engine enables access decisions based on:
- ISE security group tags
- Device type
- Location IP
- Rapid threat containment requirements
The platform integrates Cisco Talos security, threat, and vulnerability intelligence, including IP-based and URL-based security intelligence. Cisco Umbrella is included for threat visibility outside the network perimeter.
Third-party threat intelligence can be ingested and correlated through threat feeds and threat intelligence platforms using:
- STIX
- TAXII
- Selected flat file formats
The documented Threat Intelligence Director capability deconstructs imported intelligence into indicators of compromise, including:
- IPv4 addresses
- IPv6 addresses
- Domains
- URLs
- SHA-256 values
These indicators can be published to Cisco Firepower NGFW and Cisco Firepower NGIPS appliances for inline blocking or monitoring.
Multitenancy, reporting, and APIs
The FMC supports up to 50 management domains. Each domain can have separate event data, reporting, and network mapping, with access enforced through role-based controls. Policy inheritance allows lower-level policies to inherit settings from higher levels in the policy hierarchy.
Reporting and dashboard capabilities include:
- Custom dashboards
- Custom and template-based reports
- General and focused alerts
- Hyperlinked event tables, graphs, and charts
- Network behavior and performance monitoring
- System health monitoring
Four API-based integration use cases are documented:
- Export event data to platforms such as SIEM systems.
- Add third-party data to the FMC database, including vulnerability and operating system information.
- Trigger workflows and remediation actions from user-defined correlation rules.
- Permit third-party reporting and analytics systems to query FMC data.
The documented integration examples include Cisco AMP Threat Grid, Cisco Identity Services Engine, Cisco Umbrella, network access control systems, digital forensics workflows, trouble-ticketing systems, patch management, and log management.
Deployment choices and presales sizing
The FMC can be deployed as:
- A physical appliance
- A VMware virtual appliance
- A KVM virtual appliance
- An Amazon Web Services cloud deployment
Physical appliances generally provide higher sensor-management capacity and greater event storage than virtual appliances. Virtual deployment is appropriate where existing compute, storage, and operational standards favor VM-based infrastructure. Cloud deployment allows the management system to use cloud-hosted compute and storage.
Sizing should be based on four primary inputs:
- Number of physical and virtual sensors.
- Number of hosts and users represented in the network map.
- Expected security event volume.
- Expected flow rate in flows per second.
The maximum sensor count alone is not sufficient for model selection. A deployment with a lower sensor count but high event generation, large network mapping requirements, or high flow rates may require a larger appliance.
For Threat Intelligence Director on NGFWv, the datasheet recommends installing 15 GB of memory on the host hardware for optimal performance. Virtual FMC performance depends heavily on the allocated CPU, memory, storage, and overall virtual environment.
Appliance performance and capacity matrix
| Model | Max sensors | Max IPS events | Memory | CPU | Event storage | Network map hosts/users | Max flow rate | Best for |
|---|---|---|---|---|---|---|---|---|
| FMC 750 | 10 | 20 million | 8 GB | 4-core Xeon | 100 GB | 2,000/2,000 | 2,000 fps | Small deployments with limited sensor count and event volume |
| FMC 1000 | 50 | 30 million | 32 GB | 8-core Xeon | 900 GB | 50,000/50,000 | 5,000 fps | Small to medium environments requiring high availability |
| FMC 2000 | 250 | 60 million | 64 GB | 6-core Xeon | 1.8 TB | 150,000/150,000 | 12,000 fps | Medium enterprises with substantial sensor and host counts |
| FMC 2500 | 300 | 60 million | 64 GB | 2 x 8-core Xeon | 1.8 TB | 150,000/150,000 | 12,000 fps | Medium environments needing additional sensor headroom |
| FMC 4000 | 500 | 300 million | 128 GB | 2 x 10-core Xeon | 3.2 TB | 600,000/600,000 | 20,000 fps | Large enterprises with high event rates and large network maps |
| FMC 4500 | 750 | 300 million | 128 GB | 2 x 10-core Xeon | 3.2 TB | 600,000/600,000 | 20,000 fps | Largest documented physical deployments |
| FMCv | 2, 5, or 25 licensed options | 10 million | Not specified | Not specified | 250 GB | 50,000/50,000 | Varies | VM-based deployments using allocated infrastructure |
The FMCv note identifies three cost-effective virtual licensing options for managing 2, 5, or 25 sensors. The performance table lists a maximum sensor field as 25, 10, and 2, while the ordering section lists specific virtual license SKUs for 2 and 10 devices. These values should be reconciled during configuration and ordering.
Interfaces, secure boot, and resilience
The management interface is listed as 100/100/1000 RJ-45. Interface details by model are:
- FMC 750: 2 x 1 Gbps
- FMC 1000: 2 x 1 Gbps
- FMC 2000: 2 x 1 Gbps RJ-45 onboard and 2 x 10 Gbps SFP+
- FMC 2500: 2 x 1 Gbps RJ-45 onboard and 2 x 10 Gbps SFP+
- FMC 4000: 2 x 1 Gbps RJ-45 onboard and 2 x 10 Gbps SFP+
- FMC 4500: 2 x 1 Gbps RJ-45 onboard and 2 x 10 Gbps SFP+
SFPs for the 10 Gbps interfaces are ordered separately through Cisco Commerce Workplace.
Secure boot is identified as supported on:
- FMC 1000
- FMC 2500
- FMC 4500
Secure boot validates the integrity of Cisco software during appliance startup. If the software signature is missing or the software is invalid, the system does not load and boot fails.
High availability is supported on the FMC 1000, FMC 2000, FMC 2500, FMC 4000, and FMC 4500. The FMC 750 and FMCv are listed as not supporting high availability. Dual power supplies are supported on the same five physical models and are not supported on the FMC 750.
RAID configurations are:
| Model | RAID |
|---|---|
| FMC 750 | No RAID |
| FMC 1000 | HDD RAID 1 |
| FMC 2000 | HDD RAID 5 |
| FMC 2500 | HDD RAID 1 |
| FMC 4000 | SSD RAID 6 |
| FMC 4500 | SSD RAID 6 |
| FMCv | Not applicable |
Physical and environmental specifications
All physical FMC appliances use a 1RU form factor and front-to-back airflow.
| Model | Dimensions, depth x width x height | Shipping weight | Maximum power | Operating temperature |
|---|---|---|---|---|
| FMC 750 | 27.19 x 16.9 x 1.7 in; 69 x 43 x 4.3 cm | 33 lb; 15 kg | 350W | 10 C to 35 C |
| FMC 1000 | 29.8 x 16.9 x 1.7 in; 75.7 x 43 x 4.3 cm | 39 lb; 17.7 kg | 770W | 5 C to 35 C |
| FMC 2000 | 28.5 x 16.9 x 1.7 in; 72.3 x 43 x 4.3 cm | 35.6 lb; 16.2 kg | 650W | 5 C to 40 C |
| FMC 2500 | 29.8 x 16.9 x 1.7 in; 75.7 x 43 x 4.3 cm | 39 lb; 17.7 kg | 770W | 5 C to 35 C |
| FMC 4000 | 28.5 x 16.9 x 1.7 in; 72.3 x 43 x 4.3 cm | 35.6 lb; 16.2 kg | 650W | 5 C to 40 C |
| FMC 4500 | 29.8 x 16.9 x 1.7 in; 75.7 x 43 x 4.3 cm | 39 lb; 17.7 kg | 770W | 5 C to 35 C |
Power input details:
- FMC 750: 9.5 amp maximum at 110V and 50/60 Hz; 4.75 amp maximum at 220V and 50/60 Hz.
- FMC 1000: 100-240 VAC nominal, 90-264 VAC minimum/maximum; 9.5 amp maximum at 100 VAC and 4.5 amp maximum at 208 VAC.
- FMC 2000: 90-264 VAC self-ranging; 100-120 VAC nominal and 200-240 VAC nominal; 7.6 amp peak at 100 VAC and 3.65 amp peak at 208 VAC.
- FMC 2500: 100-240 VAC nominal, 90-264 VAC minimum/maximum; 9.5 amp maximum at 100 VAC and 4.5 amp maximum at 208 VAC.
- FMC 4000: 90-264 VAC self-ranging; 100-120 VAC nominal and 200-240 VAC nominal; 7.6 amp peak at 100 VAC and 3.65 amp peak at 208 VAC.
- FMC 4500: 100-240 VAC nominal, 90-264 VAC minimum/maximum; 9.5 amp maximum at 100 VAC and 4.5 amps maximum at 208 VAC.
The supplied specifications do not state MTBF values or acoustic noise levels for any physical FMC model. These values should not be used as unstated design assumptions. Rack planning must account for front-to-back airflow, maximum power draw, operating temperature, and the listed shipping weight.
Supported platforms and hypervisors
The documented managed platform combinations include:
| Managed software | Associated hardware |
|---|---|
| Firepower Threat Defense 6.x | ASA 5500-X except ASA 5585-X; Cisco 2100 Series with minimum FMC 6.2.1; Firepower 4100 Series; Firepower 9300 |
| FirePOWER Services 6.x | ASA 5500-X |
| Firepower NGIPS 6.x | Firepower 7000; Firepower 8000 |
| FirePOWER Threat Defense for ISR 6.x | 4000 Series ISR; ISR G2 |
| FirePOWER Services 5.4.x | ASA 5500-X |
| Firepower NGIPS 5.4.x | Firepower 7000; Firepower 8000 |
The FMCv hypervisor support listed in the datasheet includes:
- VMware vSphere 5.1, 5.5, and 6.0
- ESXi Server
- Optional vCenter Server
- vSphere Web Client, vSphere Client, or OVF Tool for Windows or Linux
- KVM on Ubuntu 14.04 LTS
- KVM on Red Hat Enterprise Linux 7.1
- Amazon Web Services instance types c3.xlarge and c3.2xlarge
Ordering matrix
| Part number | Product description | Best for |
|---|---|---|
| FS750-K9 | Firepower Management Center 750 chassis, 1RU | Small physical FMC deployment |
| FMC1000-K9 | Firepower Management Center 1000 chassis, 1RU | Small to medium deployment requiring HA |
| FS2000-K9 | Firepower Management Center 2000 chassis, 1RU | Medium deployment with 250-sensor capacity |
| FMC2500-K9 | Firepower Management Center 2500 chassis, 1RU | Medium deployment with 300-sensor capacity |
| FS4000-K9 | Firepower Management Center 4000 chassis, 1RU | Large deployment with high event storage |
| FMC4500-K9 | Firepower Management Center 4500 chassis, 1RU | Largest physical deployment capacity |
| FS-PWR-AC-650W= | 650W AC power supply for FS2000 and FS4000 | Spare or replacement power supply |
| FS-PWR-AC-779W= | 770W AC power supply for FMC1000, FMC2500, and FMC4500 | Spare or replacement power supply |
| FS-VMW-SW-K9 | FMC virtual VMware Firepower license | VMware-based virtual deployment |
| FS-VMW-10-SW-K9 | FMC virtual VMware Firepower license for 10 devices | Virtual deployment managing 10 devices |
| FS-VMW-2-SW-K9 | FMC virtual VMware Firepower license for 2 devices | Small virtual deployment |
Starting with FMC software version 6.0, license keys are no longer required to use the FMC. Earlier software versions require a Product Authorization Key or smart key. The physical appliance and virtual licensing SKUs must still be selected according to the intended deployment and managed-device count.
Warranty and support services
Warranty information is provided through the Cisco Product Warranties resource. The supplied datasheet does not state a warranty duration, coverage term, or specific replacement entitlement.
Cisco Smart Net Total Care support provides:
- Global access to Cisco Technical Assistance Center engineers
- Access to Cisco.com knowledge resources, tools, and technical content
- Hardware replacement options including 2-hour, 4-hour, and Next-Business-Day advance replacement
- Return For Repair service
- Operating system software updates within the licensed feature set
- Proactive diagnostics and real-time alerts on selected devices through Cisco Smart Call Home
Smart Net Total Care Onsite Service is an optional service that provides a field engineer to install replacement parts at the customer location and assist with restoring operation.
Support selection should be aligned with the FMC appliance role, high-availability design, replacement logistics, rack location, and required recovery objectives. Physical models with dual power and RAID provide more hardware resilience than the FMC 750. The FMCv requires support planning across the virtual infrastructure, storage platform, hypervisor, and cloud or data-center operating model.