Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, is the centralized administrative and policy platform for Cisco Secure Firewall Threat Defense, Cisco Secure IPS, Cisco Firepower Threat Defense for ISR, and Cisco Malware Defense. It consolidates firewall administration, application control, intrusion prevention, URL filtering, malware protection, event correlation, reporting, network discovery, and operational monitoring into a common management plane.
FMC can be deployed as a physical appliance, virtual appliance, cloud-delivered service, or consumed as a service through CDO. Physical models are selected according to the number of sensors, network map size, event rate, IPS event volume, and local event storage requirements. Virtual models provide the same management capabilities as physical appliances, with sizing determined by assigned compute, memory, storage, deployment platform, and expected event load.
Management scope and operating model
FMC is designed to provide centralized management for distributed security controls. A single policy framework can address firewall access, application control, threat prevention, URL filtering, and advanced malware protection. Policies can be applied consistently across multiple managed security solutions, reducing duplicated configuration and improving administrative control.
The platform provides visibility into users, applications, devices, network behavior, security events, and changing network resources. Its operational views include:
- High-level security trends and statistics
- Detailed event information
- Compliance and forensic data
- Device health and operational status
- Network maps showing hosts and users
- Custom dashboards and reports
- Hyperlinked tables, graphs, and charts
- Exportable workflow and incident data
Network Discovery uses passive traffic analysis to identify users, applications, and devices. This information provides environmental context for security events and assists with tuning intrusion prevention signature sets to the systems actually present in the network. The platform also supports integration with third-party vulnerability management systems.
Security teams can use the discovered environment to evaluate the effect of an event, identify affected hosts, and apply controls based on the specific application, user, device, location, threat intelligence indicator, or network condition involved.
Policy control and administrative separation
FMC supports role-based access control and separation of duties. Administrative personas can be created for functions such as NetOps and SecOps, with each user receiving only the permissions required for assigned responsibilities.
The platform supports up to 100 management domains. Each domain can maintain separate event data, reporting, and network mapping. Role-based access control governs access to these domains. Policy inheritance allows higher-level policies to be passed through the policy hierarchy, supporting consistent administration across organizational units or managed environments.
Integrated identity-based policy controls include Azure AD user and group based access control with Cisco Identity Services Engine integration. Access decisions can use Cisco ISE security group tags, device type, location IP, and related identity context.
This architecture is suitable for organizations that require:
- Separate operational ownership between network and security teams
- Delegated administration for business units or customers
- Central policy governance with local operational control
- Consistent policy inheritance across multiple environments
- Identity-aware access policy enforcement
- Centralized audit and reporting boundaries
Threat detection and automated response
FMC correlates security events with network vulnerabilities and other contextual data to prioritize attacks that may have succeeded. This allows security teams to focus investigation on events with the greatest potential impact.
The platform correlates data from network, endpoint, intrusion, and security intelligence sources. It can identify hosts showing indicators of compromise associated with otherwise unknown attacks. Event correlation can also initiate automated responses through:
- Syslog
- SNMP
- Remediation modules
File policies can apply criteria that cause a file to be analyzed for known malware or submitted to an integrated sandbox for analysis of unknown malware. Built-in forensic capabilities provide detailed analysis and graphical representation of devices affected by a malware outbreak.
Threat intelligence can be sourced from Cisco Talos and third-party feeds. Supported third-party intelligence formats include STIX, TAXII, and flat files. Both IP-based and URL-based security intelligence can be ingested and correlated.
Application visibility and control supports precise control over thousands of commercial applications. Open App ID can be used for detailed identification and control of custom applications.
Dynamic policy and workload integration
Cisco Secure Dynamic Attribute Connector, or CSDAC, runs natively within FMC from release 7.4 onward. It provides automated policy management for environments where IP addresses and workload locations change frequently.
CSDAC can source workload tags from:
- AWS
- Microsoft Azure
- Google Cloud Platform
- VMware
It can create dynamic objects for policy enforcement and integrate with SaaS services including Office365, GitHub, Azure Service Tags, Zoom, and WebEx. Generic text file driven IP prefixes are also supported for open integration. Example data sources include known IP lists and vulnerable IP lists.
The principal engineering benefit is reduced dependence on repeated manual policy updates and redeployment when workloads move or addresses change. Virtual FMC deployments using CSDAC should be provisioned with an additional 2 vCPUs and 2 GB of RAM beyond the standard FMCv memory requirement.
Cisco Secure Workload integration extends visibility and policy enforcement across network and workload environments. This is intended for distributed and dynamic applications where consistent controls must be applied across infrastructure boundaries.
Integration and API capabilities
FMC provides open APIs for integration with external security, analytics, reporting, and remediation systems. API use cases include:
- Exporting event data to a SIEM platform
- Enriching Cisco IPS data with third-party vulnerability information
- Querying the FMC database for reporting and analytics
- Starting remediation workflows from user-defined correlation rules
- Integrating with network access control systems
- Quarantining infected endpoints
- Initiating digital forensic processes
Cisco integrations include Cisco Secure Malware Analytics for sandboxing, Cisco ISE for identity and segmentation data, and Cisco Umbrella for domain visibility.
SecureX integration provides a ribbon within FMC for pivoting from FMC incidents into SecureX workflows. SecureX Threat Response can query sightings for investigated IP addresses, combine Cisco Talos and third-party intelligence, and provide additional incident context. SecureX Orchestrator can invoke FMC API calls to automate routine tasks.
Cisco Security Analytics and Logging integration provides a scalable view of firewall log management, behavioral analysis, real-time threat detection, and continuous analysis of security activity.
Deployment choices and virtual infrastructure
FMC is available in the following deployment forms:
- Physical FMC appliance
- FMC Virtual appliance
- Cloud-delivered FMC through CDO
- Service-consumed deployment
The cloud-delivered option removes the requirement for the customer to manage FMC software updates. Compatibility, supported versions, deployment requirements, and browser requirements are governed by the applicable release documentation.
All FMC Virtual models use the same base memory guidance: 32 GB recommended and 28 GB required. The virtual appliance can operate on the following platforms and cloud environments:
| Platform | Supported configuration |
|---|---|
| VMware vSphere | ESXi Server 5.1, 5.5, 6.0, 6.5, 6.7, and 7.0; vCenter Server optional |
| KVM | Ubuntu 18.04 LTS and Red Hat Enterprise Linux version 7.1 |
| AWS | c3.4xlarge with 16 vCPUs and 30 GB; c4.4xlarge with 16 vCPUs and 30 GB; c5.4xlarge with 16 vCPUs and 32 GB |
| Microsoft Azure | Standard_D4_v2 with 8 vCPUs and 28 GB |
| GCP | c2-standard-8 with 8 vCPUs and 32 GB; c2-standard-16 with 16 vCPUs and 64 GB |
| OCI | VM.Standard 2.4 with 60 GB |
| Nutanix | Nutanix AHV |
| Hyperflex | Release 4.5(1a); 4 to 8 vCPUs and 28 to 32 GB for FMCv-2, FMCv-10, and FMCv-25; 32 vCPUs and 64 GB for FMCv-300 |
OpenStack is also listed as a supported platform for the FMCv(2/10/25) virtual model family.
Physical model selection
The physical appliances provide the same management capabilities. Selection is based on managed sensor count, IPS event volume, event rate, network map size, event storage, and required interface capacity.
| Model | Sensors managed | Maximum IPS events | Maximum event rate | Network map hosts/users | Memory | Event storage | Best For |
|---|---|---|---|---|---|---|---|
| FMC 1700 | 50 | 30 million | 5,000 eps | 50,000 / 50,000 | 32 GB | 900 GB | Small and midsize environments with up to 50 sensors and moderate event rates |
| FMC 2700 | 300 | 60 million | 12,000 eps | 150,000 / 150,000 | 64 GB | 1.8 TB | Enterprise environments requiring management of up to 300 sensors |
| FMC 4700 | 1,000 | 400 million | 30,000 eps | 600,000 / 600,000 | 128 GB | 3.2 TB | Large enterprise and service provider environments with high sensor and event volumes |
The event rate and IPS event maximum should be evaluated independently. A deployment may fit within the sensor count while exceeding the expected event rate or long-term event storage requirement. Presales sizing should therefore collect all four values: managed sensors, events per second, projected IPS event volume, and network map size.
Virtual model selection
| Model | Sensors managed | Maximum IPS events | CPU | Memory | Event storage | Network map hosts/users | Maximum event rate | Best For |
|---|---|---|---|---|---|---|---|---|
| FMCv2 | 2 | 10 million | 8 or 4 vCPUs | 32 GB | 250 GB | 50,000 / 50,000 | Varies | Small deployments with two managed sensors |
| FMCv10 | 10 | 10 million | 8 or 4 vCPUs | 32 GB | 250 GB | 50,000 / 50,000 | Varies | Small branch or departmental environments |
| FMCv25 | 25 | 10 million | 8 or 4 vCPUs | 32 GB | 250 GB | 50,000 / 50,000 | Varies | Midsize environments requiring up to 25 sensors |
| FMCv300 | 300 | 60 million | 32 vCPUs | 64 GB | 2.2 TB | 150,000 / 150,000 | 12,000 eps | Enterprise deployments requiring up to 300 sensors |
FMCv(2/10/25) supports VMware, KVM, AWS, Azure, GCP, OCI, Nutanix, Hyperflex, and OpenStack. FMCv300 supports VMware, AWS, and OCI.
High availability is supported for FMCv(2/10/25) on VMware, AWS, and OCI, but it is not supported on FMCv2. FMCv300 supports high availability on VMware, AWS, and OCI.
The FMCv(2/10/25) table reports a variable maximum event rate rather than a fixed value. This must be treated as a sizing constraint requiring validation against the intended deployment and current release documentation. The FMCv300 model has a stated maximum of 12,000 events per second.
Physical interfaces and storage
All three physical models provide:
- Two built-in 10GbE RJ45 OCP3.0 network interfaces
- Support for 100 Mbps, 1 Gbps, and 10 Gbps on the management interface
- Eth0 as the primary management port
- Eth1, eth2, and eth3 available as secondary management or event ports
- Two USB 3.0 Type A ports
- One VGA port using a 15-pin DB-15 connector
- Two fixed SFP+ ports
- Two onboard 1 Gbps RJ45 interfaces
- Secure boot
- High availability support
The FMC 1700 and FMC 2700 provide two 10 Gbps SFP+ interfaces. The FMC 4700 provides two 10/25 Gbps SFP+ interfaces. SFP modules are ordered separately through Cisco Commerce Workplace.
Supported optics are:
| Model | Supported SFP options |
|---|---|
| FMC 1700 | SFP-10G-SR and SFP-10G-LR |
| FMC 2700 | SFP-10G-SR and SFP-10G-LR |
| FMC 4700 | SFP-10G-SR, SFP-10G-LR, SFP-25G-SR-S, SFP-10/25G-LR-S, and SFP-10/25G-CSR-S |
Storage designs differ by model:
| Model | Drive configuration | RAID | Service characteristic |
|---|---|---|---|
| FMC 1700 | Two 1.2 TB 10-K SAS HDDs | RAID-1 | Hot swappable |
| FMC 2700 | Four 600 GB 10-K SAS HDDs | RAID 5 | Hot swappable |
| FMC 4700 | Ten 1.2 TB 10-K SAS HDDs | RAID-6 | Hot swappable |
Each chassis has a dedicated internal riser for a PCIe-style Cisco modular RAID controller card. The RAID controller is an internal component and is not field replaceable. Memory modules are also internal and not field replaceable.
Physical, environmental, and reliability considerations
All physical models use a 1RU form factor and front-to-back airflow. The dimensions are 30 x 16.9 x 1.7 inches, or 76.2 x 42.9 x 4.3 centimeters.
| Model | Shipping weight | Maximum watts | Operating temperature |
|---|---|---|---|
| FMC 1700 | 32.2 lb, 16.6 kg | 1,050 W | 50 F to 95 F, 10 C to 35 C |
| FMC 2700 | 34.1 lb, 16.8 kg | 1,050 W | 50 F to 95 F, 10 C to 35 C |
| FMC 4700 | 36 lb, 17.0 kg | 1,050 W | 50 F to 95 F, 10 C to 35 C |
Each physical appliance uses two 1050 W AC power supplies. The supplies are hot swappable and redundant in a 1+1 configuration. The stated power consumption is 2626 BTU/hr.
The power supply specification is:
- Nominal input: 100-240 VAC
- Minimum and maximum input range: 90-264 VAC
- Maximum current at 100 VAC: 9.2 amps
- Maximum current at 230 VAC: 5.2 amps
The datasheet does not specify MTBF or acoustic noise values. These values must not be used as unverified design assumptions. For rack planning, the documented requirements are 1RU clearance, front-to-back airflow, the stated operating temperature range, dual AC power availability, and a maximum input power rating of 1,050 W per appliance.
The maximum power rating should be used for electrical and thermal planning. The stated BTU/hr value should be used for data center heat-load calculations. The two power supplies support power redundancy, but the appliance still requires appropriate upstream power circuits and rack-level airflow management.
Secure boot is supported on all physical models. During startup, the hardware validates the integrity of Cisco software. If a required signature is missing or the software is invalid, the system will not load it and boot will fail.
Presales sizing rules
Use the following sequence when sizing FMC:
- Count all physical and virtual sensors that will be managed.
- Estimate the sustained and peak security event rate in events per second.
- Estimate total IPS event volume retained or processed.
- Count hosts and users represented in the network map.
- Determine the required local event storage period.
- Identify whether high availability is required.
- Select physical or virtual deployment based on data center, cloud, and operational requirements.
- Validate interface speed and optical requirements.
- Confirm power, thermal, rack, and airflow capacity for physical appliances.
- Confirm hypervisor and cloud compatibility for virtual appliances.
- Add the additional compute requirement when CSDAC is used with FMCv.
- Verify that the selected model supports the intended policy domains, integrations, and administrative separation model.
Do not select a model using sensor count alone. For example, a deployment may be within the sensor limit of the FMC 2700 but exceed its 12,000 events per second maximum, its 60 million IPS event maximum, or its 150,000 host and 150,000 user network map capacity.
Ordering and warranty
Ordering and licensing information for physical appliances, virtual appliances, and cloud-delivered service is provided through the Cisco Network Security Ordering Guide. The datasheet does not list individual commercial license part numbers or a complete bill of materials. SFP modules are ordered separately through Cisco Commerce Workplace.
Warranty information is referenced through the Cisco.com Product Warranties page. The datasheet does not state a warranty duration, hardware replacement entitlement, response time, software support term, or service-level commitment. Those terms must be obtained from the applicable warranty and service documentation associated with the order.
Service planning should distinguish between:
- Hardware warranty coverage
- Software support and maintenance
- Technical assistance
- Replacement hardware logistics
- Software update entitlement
- Cloud service operations
- Optional professional or managed services
The specific entitlement depends on the selected product, license, warranty, and service package.