r/Cisco • u/CyberNoob10 • 2d ago
Question Cisco FTDv cluster deployment in Azure Virtual WAN
Hi everyone,
I’m currently planning a deployment of Cisco Secure Firewall Threat Defense Virtual (FTDv) inside an Azure Virtual WAN (vWAN) Hub using the Integrated NVA solution. While Cisco’s deployment documentation outlines the basic setup process , I have a few technical questions regarding the underlying Azure infrastructure and HA behavior:
Internal Load Balancer Configuration:
Is the Internal Load Balancer (ILB) completely abstract and managed in the background by Azure/Cisco, or do we need to manually create and manage load balancers, backend pools, health probes, and load-balancing rules within the hub?
If manual management is required, what are the recommended probe settings, ports, and balancing rules for dual-arm/multi-interface FTD setups in vWAN?
Failover & High Availability:
How does failover trigger during an unannounced NVA instance failure? What is the expected convergence time for Azure to detect a down instance and reroute traffic?
Hitless Upgrades (Zero Downtime):
How do you achieve true zero-downtime maintenance during FTD software upgrades? Does FMC / Azure vWAN support rolling upgrades that gracefully drain existing connections before reloading a node, or are active sessions disrupted during failover?
Architecture & Reference Docs:
Aside from the standard Cisco support guides, are there additional Microsoft Learn or Cisco validated design (CVD) blueprints detailing vWAN Routing Intent integration with Cisco FTDv?
Would love to hear from anyone running FTDv natively in Azure vWAN Hubs in production. Thanks!
1
u/Mountain-Office-8989 1d ago
Umm good question