<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD ECMP with multiple interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326811#M1064186</link>
    <description>&lt;P&gt;Thanks Bogdan, I just tried it and it works like a charm!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;FMC doc under ECMP routing says it is not supported across different interfaces.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/routing_overview_for_firepower_threat_defense.html#ID-2101-0000004d" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/routing_overview_for_firepower_threat_defense.html#ID-2101-0000004d&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is the same text as ASA doc before the zone feature was introduced, they just forgot to correct it. They should have a reference to the FlexConfig zone name ecmp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
    <pubDate>Wed, 07 Feb 2018 16:10:49 GMT</pubDate>
    <dc:creator>Patrick Moubarak</dc:creator>
    <dc:date>2018-02-07T16:10:49Z</dc:date>
    <item>
      <title>FTD ECMP with multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326750#M1064180</link>
      <description>&lt;P&gt;ASA 9.3(2) introduced the concept of zones with ECMP support across different interfaces (in the same zone):&lt;/P&gt;
&lt;P&gt;You can group interfaces together into a traffic zone to accomplish traffic load balancing (using Equal Cost Multi-Path (ECMP) routing), route redundancy, and asymmetric routing across multiple interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea when FTD will support this? the interface zone in FMC seems to be for Snort, not for ASA Lina, only nameif is present in Lina CLI:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;firepower# show nameif &lt;BR /&gt;Interface Name Security&lt;BR /&gt;Ethernet1/5 inside1 0&lt;BR /&gt;Ethernet1/6 inside2 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;firepower# show zone&lt;BR /&gt;firepower#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EIGRP neighbors come up on both interfaces but routes are only present on inside1.&lt;/P&gt;
&lt;P&gt;Is there a recommended design for FTD using L3 routing to 2 Nexus switches? I can't have EIGRP neighbors on vPC VLANs... so I opted for L3 routed interfaces between the 2 Nexus and between each Nexus and FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:18:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326750#M1064180</guid>
      <dc:creator>Patrick Moubarak</dc:creator>
      <dc:date>2020-02-21T15:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: FTD ECMP with multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326789#M1064182</link>
      <description>&lt;P&gt;You could use FlexConfig.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to configure Equal-Cost-Multi-Path (ECMP) routing using traffic zones, the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;zone&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;command differs for&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Firepower Threat Defense&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;devices compared to the one used on ASA. Although you can still follow the instructions in the ASA general configuration guide, use&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;zone&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="var"&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;ecmp&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;instead of the ASA version of the command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/flexconfig_policies.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/flexconfig_policies.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bogdan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 15:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326789#M1064182</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2018-02-07T15:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: FTD ECMP with multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326811#M1064186</link>
      <description>&lt;P&gt;Thanks Bogdan, I just tried it and it works like a charm!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;FMC doc under ECMP routing says it is not supported across different interfaces.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/routing_overview_for_firepower_threat_defense.html#ID-2101-0000004d" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/routing_overview_for_firepower_threat_defense.html#ID-2101-0000004d&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is the same text as ASA doc before the zone feature was introduced, they just forgot to correct it. They should have a reference to the FlexConfig zone name ecmp.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Patrick&lt;/P&gt;</description>
      <pubDate>Wed, 07 Feb 2018 16:10:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3326811#M1064186</guid>
      <dc:creator>Patrick Moubarak</dc:creator>
      <dc:date>2018-02-07T16:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD ECMP with multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3772888#M1064190</link>
      <description>&lt;P&gt;Hello Patrick&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN&gt;Do you still have the script to configure the FlexConfig policy?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;Can you share it, please?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 13:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/3772888#M1064190</guid>
      <dc:creator>diogo_1203</dc:creator>
      <dc:date>2019-01-04T13:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTD ECMP with multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/4195092#M1076504</link>
      <description>&lt;P&gt;This worked for me:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zone &amp;lt;&lt;EM&gt;zone-name&lt;/EM&gt;&amp;gt; ecmp&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface EthernetX/X&lt;BR /&gt;&amp;nbsp; zone-member &amp;lt;&lt;EM&gt;zone-name&lt;/EM&gt;&amp;gt;&lt;BR /&gt;interface EthernetY/Y&lt;BR /&gt;&amp;nbsp; zone-member &amp;lt;&lt;EM&gt;zone-name&lt;/EM&gt;&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 11:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/4195092#M1076504</guid>
      <dc:creator>michal.nehasil</dc:creator>
      <dc:date>2020-12-08T11:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD ECMP with multiple interfaces</title>
      <link>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/4677964#M1093025</link>
      <description>&lt;P&gt;Hi all, A FYI Warning.&amp;nbsp; I just did the FMC upgrade to 7.2 and push policy as per the process.&amp;nbsp; My FTD's all lost their Zone config and everything went to S41t.&amp;nbsp; Devices were still running 7.0.&amp;nbsp; FMC 7.2 has added Zones to the Device -&amp;gt; Routing - ECMP.&amp;nbsp; recreate the Zones and assigned the interfaces here.&amp;nbsp; Then remove the flex config from the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 08:42:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-ecmp-with-multiple-interfaces/m-p/4677964#M1093025</guid>
      <dc:creator>Damon Kalajzich</dc:creator>
      <dc:date>2022-08-29T08:42:19Z</dc:date>
    </item>
  </channel>
</rss>

