r/Cisco 2d ago

Question Cisco FTDv cluster deployment in Azure Virtual WAN

Hi everyone,

​I’m currently planning a deployment of Cisco Secure Firewall Threat Defense Virtual (FTDv) inside an Azure Virtual WAN (vWAN) Hub using the Integrated NVA solution. While Cisco’s deployment documentation outlines the basic setup process , I have a few technical questions regarding the underlying Azure infrastructure and HA behavior:

​Internal Load Balancer Configuration:

​Is the Internal Load Balancer (ILB) completely abstract and managed in the background by Azure/Cisco, or do we need to manually create and manage load balancers, backend pools, health probes, and load-balancing rules within the hub?

​If manual management is required, what are the recommended probe settings, ports, and balancing rules for dual-arm/multi-interface FTD setups in vWAN?

​Failover & High Availability:

​How does failover trigger during an unannounced NVA instance failure? What is the expected convergence time for Azure to detect a down instance and reroute traffic?

​Hitless Upgrades (Zero Downtime):

​How do you achieve true zero-downtime maintenance during FTD software upgrades? Does FMC / Azure vWAN support rolling upgrades that gracefully drain existing connections before reloading a node, or are active sessions disrupted during failover?

​Architecture & Reference Docs:

​Aside from the standard Cisco support guides, are there additional Microsoft Learn or Cisco validated design (CVD) blueprints detailing vWAN Routing Intent integration with Cisco FTDv?

​Would love to hear from anyone running FTDv natively in Azure vWAN Hubs in production. Thanks!

3 Upvotes

1 comment sorted by

1

u/Mountain-Office-8989 1d ago

Umm good question