<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FP Diagnostic interface setting up in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4033610#M1066844</link>
    <description>&lt;P&gt;Finally got things working.&amp;nbsp;First thing indeed was to create static route and the second is to add SNMP host via diagnostic interface in Platform Settings.&lt;/P&gt;&lt;P&gt;Resolved yesterday with TAC helping but thank you Marvin as well, appreciate it.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 11:06:15 GMT</pubDate>
    <dc:creator>voipleo</dc:creator>
    <dc:date>2020-02-21T11:06:15Z</dc:date>
    <item>
      <title>FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4028172#M933278</link>
      <description>&lt;P&gt;Trying to enable diagnostic interface on FP 2100 for gathering information over SNMP. The interface itself marked green in FMC and static IP address is set up but neither ICMP or SNMP to this interface are not responding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Management interface itself is working fine and located in the same network as diagnostic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show interface ip brief&lt;BR /&gt;Management1/1 10.1.1.146 YES manual up up&lt;/P&gt;&lt;P&gt;# show running-config interface Management1/1&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;nameif diagnostic&lt;BR /&gt;cts manual&lt;BR /&gt;propagate sgt preserve-untag&lt;BR /&gt;policy static sgt disabled trusted&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 10.1.1.146 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The related guide I found is&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/212420-configure-firepower-threat-defense-ftd.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/212420-configure-firepower-threat-defense-ftd.html&lt;/A&gt; but it is not so clear.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4028172#M933278</guid>
      <dc:creator>voipleo</dc:creator>
      <dc:date>2020-02-21T17:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4028249#M933279</link>
      <description>&lt;P&gt;When you assigned the Diagnostic interface an address in FMC did you also name it MANAGEMENT?&lt;/P&gt;
&lt;P&gt;Are you trying to reach the interface from someplace other than the local subnet it's in? If so you need to setup a route to tell the management interface what gateway to use. Verify it once set with "show route management-only" from the LINA cli.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 14:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4028249#M933279</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-02-12T14:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4028283#M933280</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I renamed it to Management, no changes, does name matter?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fp diag.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67074i3758D37AE4743D24/image-size/large?v=v2&amp;amp;px=999" role="button" title="fp diag.png" alt="fp diag.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yes, I'm trying to reach from different network but I can't even ping this IP from lina cli itself. Also please kindly tell where should I write a route for diagnostic interface. I can reach management interface which in the same network as diagnostic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 15:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4028283#M933280</guid>
      <dc:creator>voipleo</dc:creator>
      <dc:date>2020-02-12T15:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4032998#M943543</link>
      <description>&lt;P&gt;Sorry for the delay, I wanted to lab this up to confirm.&lt;/P&gt;
&lt;P&gt;Make sure your device platform settings are setup to allow SNMP from the desired host(s) and that you've assigned the policy to your target device(s):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD SNMP Platform settings.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67730iBBF23F0793CD9DF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD SNMP Platform settings.PNG" alt="FTD SNMP Platform settings.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE:&lt;/STRONG&gt; I found that you should only use a single interface. Specifying multiples resulted in only the first one getting pushed in to the running-config. This was with Firepower 6.5.0.2.&lt;/P&gt;
&lt;P&gt;Setup a static route for the diagnostic interface. It should appear in the running-config as a "management-only" route:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD Mgmt and Diagnostic route.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67727i68B28AA5C22D7518/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD Mgmt and Diagnostic route.PNG" alt="FTD Mgmt and Diagnostic route.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you have done that, your should be able to get SNMP data from a remote subnet.&lt;/P&gt;
&lt;P&gt;Here it is shown via cli:&lt;/P&gt;
&lt;PRE&gt;root@fmc:/usr/share/snmp/mibs# snmpwalk -v 2c -c ccielab 172.31.4.4 1.3.6.1.4.1.9.9   
SNMPv2-SMI::enterprises.9.9.41.1.1.1.0 = Counter32: 0
SNMPv2-SMI::enterprises.9.9.41.1.1.2.0 = INTEGER: 0
SNMPv2-SMI::enterprises.9.9.41.1.1.3.0 = INTEGER: 0
SNMPv2-SMI::enterprises.9.9.41.1.1.4.0 = Counter32: 0
SNMPv2-SMI::enterprises.9.9.41.1.1.5.0 = Counter32: 0
SNMPv2-SMI::enterprises.9.9.41.1.1.6.0 = INTEGER: 3
SNMPv2-SMI::enterprises.9.9.41.1.1.7.0 = STRING: "vftd-new.ccielab.mrneteng.com"
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;...and via a GUI tool from the other authorized host:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD SNMP Interface scan.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/67728iD0F50BEBAC244A0D/image-size/large?v=v2&amp;amp;px=999" role="button" title="FTD SNMP Interface scan.PNG" alt="FTD SNMP Interface scan.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2020 14:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4032998#M943543</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-02-20T14:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4033610#M1066844</link>
      <description>&lt;P&gt;Finally got things working.&amp;nbsp;First thing indeed was to create static route and the second is to add SNMP host via diagnostic interface in Platform Settings.&lt;/P&gt;&lt;P&gt;Resolved yesterday with TAC helping but thank you Marvin as well, appreciate it.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4033610#M1066844</guid>
      <dc:creator>voipleo</dc:creator>
      <dc:date>2020-02-21T11:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4058876#M1068723</link>
      <description>Hi, How do you get the diagnostic interface and management interface on the same network or subnet? I keep getting errors for overlapping network.</description>
      <pubDate>Sat, 04 Apr 2020 03:34:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4058876#M1068723</guid>
      <dc:creator>ernesto_tello</dc:creator>
      <dc:date>2020-04-04T03:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: FP Diagnostic interface setting up</title>
      <link>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4058886#M1068724</link>
      <description>&lt;P&gt;The overlapping bit is usually seen when you are using the same subnet for management and inside (or other data interface) (which is OK on Firepower) and then adding an IP to the diagnostic (which it won't accept in that case).&lt;/P&gt;
&lt;P&gt;By definition management and diagnostic will always be on the same subnet since they are using the same physical interface and not trunking.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Apr 2020 03:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fp-diagnostic-interface-setting-up/m-p/4058886#M1068724</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-04T03:49:32Z</dc:date>
    </item>
  </channel>
</rss>

