We’re rolling out Cisco Firepower to manage firewalls across multiple branch offices. My team needs to apply a standard security policy—like blocking certain categories and allowing specific apps—to over 50 FTD devices.
I’ve looked into FMC, but I’m unsure about the best way to ensure consistency without manual errors. How do you handle policy deployment at this scale?
Specifically:
- Do you use device groups and shared policies, or template policies?
- What’s your process for testing a policy before pushing to all devices?
- Any pitfalls with version upgrades or preemption during deployment?
Device groups and templates sound good until you hit a branch with one weird legacy app. Then you're either making exceptions that break the model or bending the policy until it's not standard anymore.
You need a lab device that mirrors your most complex site, not just a test policy. Push there first and actually run traffic through it for a week. The preemption issue is real - if someone else deploys while you're deploying, you get conflicts and half-applied policies. Lock down deployment rights.
Honestly, after 50 devices, the FMC interface starts to fight you. I've seen teams script the API for bulk changes just to avoid the GUI timeout. Have you looked at that, or are you stuck in the web UI?
Just my 2 cents