<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA CLI - trouble with Conft in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202903#M1065333</link>
    <description>&lt;P&gt;I've not had to do it "in the wild" yet but it should be possible according to the FMC and FTD site-to-site VPN documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/622/configuration/guide/fpmc-config-guide-v622/firepower_threat_defense_site_to_site_vpns.html#reference_nwy_fhl_wy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/622/configuration/guide/fpmc-config-guide-v622/firepower_threat_defense_site_to_site_vpns.html#reference_nwy_fhl_wy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However I just tried it in my lab and was unable to get it to work there as well (running the latest FMC and FTD 6.2.2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've asked among my peers in the partner community to see if it's one of those bits that's not quite working yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding ASA vs. FTD image type if you go with ASA you would lose all of the ability to to NGIPS (Snort etc. ) inspections and management would be via the old style ASA cli or ADSM GUI. That's a pretty major change to the appliance and not one to be undertaken lightly. The option is there though should you decide FTD is not cutting it for you at this time.&lt;/P&gt;</description>
    <pubDate>Sat, 21 Oct 2017 13:58:05 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-10-21T13:58:05Z</dc:date>
    <item>
      <title>ASA CLI - trouble with Conft</title>
      <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202766#M1065330</link>
      <description>&lt;P&gt;Hi Guys,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Feeling rather noobish on this one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i`m having trouble finding the Conf t, the device is ASA 2110&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I`ve tried connecting to FTD &amp;amp; Local Mgmt and i can see the config - but i cant edit it&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;geg01#&lt;BR /&gt; acknowledge Acknowledge&lt;BR /&gt; backup Backup&lt;BR /&gt; clear Clear managed objects&lt;BR /&gt; commit-buffer Commit transaction buffer&lt;BR /&gt; connect Connect to Another CLI&lt;BR /&gt; discard-buffer Discard transaction buffer&lt;BR /&gt; end Go to exec mode&lt;BR /&gt; exit Exit from command interpreter&lt;BR /&gt; scope Changes the current mode&lt;BR /&gt; set Set property values&lt;BR /&gt; show Show system information&lt;BR /&gt; terminal Set terminal line parameters&lt;BR /&gt; top Go to the top mode&lt;BR /&gt; up Go up one mode&lt;BR /&gt; where Show information about the current mode&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;geg01# connect&lt;BR /&gt; ftd Connect to FTD Application CLI&lt;BR /&gt; local-mgmt Connect to Local Management CLI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202766#M1065330</guid>
      <dc:creator>RowC</dc:creator>
      <dc:date>2020-02-21T14:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CLI - trouble with Conft</title>
      <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202790#M1065331</link>
      <description>&lt;P&gt;It appears you are logging into a Firepower 2110 running FTD image. You cannot modify FTD configuration (apart from the minimal setup of the network) from the cli.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need to use either the on-box Firepower Device Manager or a remote Firepower Management Center. In either case you connect to the management interface you have assigned (via Firepower Chassis Manager) to the FTD logical device - not to the chassis management interface.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2017 04:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202790#M1065331</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-21T04:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CLI - trouble with Conft</title>
      <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202797#M1065332</link>
      <description>&lt;P&gt;Thanks Marvin !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I`m trying to set up Ipsec tunnels from a dynamic IP address to the static ip of the ASA, The &lt;SPAN&gt;on-box Firepower Device Manager seems limited, You mentioned the Firepower running the FTD image - would running a different Image provide greater flexibility&amp;nbsp;?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2017 04:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202797#M1065332</guid>
      <dc:creator>RowC</dc:creator>
      <dc:date>2017-10-21T04:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CLI - trouble with Conft</title>
      <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202903#M1065333</link>
      <description>&lt;P&gt;I've not had to do it "in the wild" yet but it should be possible according to the FMC and FTD site-to-site VPN documentation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/622/configuration/guide/fpmc-config-guide-v622/firepower_threat_defense_site_to_site_vpns.html#reference_nwy_fhl_wy" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/622/configuration/guide/fpmc-config-guide-v622/firepower_threat_defense_site_to_site_vpns.html#reference_nwy_fhl_wy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However I just tried it in my lab and was unable to get it to work there as well (running the latest FMC and FTD 6.2.2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've asked among my peers in the partner community to see if it's one of those bits that's not quite working yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding ASA vs. FTD image type if you go with ASA you would lose all of the ability to to NGIPS (Snort etc. ) inspections and management would be via the old style ASA cli or ADSM GUI. That's a pretty major change to the appliance and not one to be undertaken lightly. The option is there though should you decide FTD is not cutting it for you at this time.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Oct 2017 13:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3202903#M1065333</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-21T13:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CLI - trouble with Conft</title>
      <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3203238#M1065334</link>
      <description>&lt;P&gt;Hi Marvin,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What be a acceptable method of connecting from a dynamic IP address to the cisco 2110 then ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking i could find an any connect client to run on the IOS - i think i might have been dreaming..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Chris&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 02:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3203238#M1065334</guid>
      <dc:creator>RowC</dc:creator>
      <dc:date>2017-10-23T02:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA CLI - trouble with Conft</title>
      <link>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3203248#M1065335</link>
      <description>&lt;P&gt;I haven't received official word from Cisco engineering, but I am beginning to think it may not be a feature that is currently implemented. Two other engineers (not Cisco employees) have told me that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I suggest you open a TAC case for confirmation.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2017 02:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cli-trouble-with-conft/m-p/3203248#M1065335</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-23T02:59:58Z</dc:date>
    </item>
  </channel>
</rss>

