<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 5508-x &amp;amp; SFR - mgmt interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117884#M1071995</link>
    <description>&lt;P&gt;The ASA and SFR module share the management interface.&amp;nbsp; The IP subnet of both the ASA and SFR mgmt interface must be the same though.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="p_H_Head3"&gt;ASA 5506-X (9.6 and Earlier) through ASA 5555-X (Software Module) in Routed Mode&lt;/H3&gt;
&lt;P class="pN1_Note1"&gt;&lt;A name="pgfId-152957" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="9" height="2" /&gt;&lt;/A&gt;: The ASA 5506-X and 5512-X do not support the FirePOWER module in 9.10 and later.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-152964" target="_blank"&gt;&lt;/A&gt;These models run the ASA FirePOWER module as a software module, and the ASA FirePOWER module shares the Management 0/0 or Management 1/1 interface (depending on your model) with the ASA.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-144843" target="_blank"&gt;&lt;/A&gt;All management traffic to and from the ASA FirePOWER module must enter and exit the Management interface. The ASA FirePOWER module also needs Internet access. Management traffic cannot pass through the ASA over the backplane; therefore you need to physically cable the management interface to an ASA interface to reach the Internet.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-145520" target="_blank"&gt;&lt;/A&gt;If you do not configure a name and IP address in the ASA configuration for Management, then the interface belongs exclusively to the module. In this case, the Management interface is not a regular ASA interface, and you can:&lt;/P&gt;
&lt;P class="pNF_NumFirst"&gt;&lt;A name="pgfId-144890" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="10" height="2" /&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Configure the ASA FirePOWER IP address to be on the same network as a regular ASA data interface.&lt;/P&gt;
&lt;P class="pNN_NumNext"&gt;&lt;A name="pgfId-144905" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="10" height="2" /&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Specify the data interface as the ASA FirePOWER gateway.&lt;/P&gt;
&lt;P class="pNN_NumNext"&gt;&lt;A name="pgfId-144907" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;3.&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="10" height="2" /&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Directly connect the Management interface to the data interface (using a Layer2 switch).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Jul 2020 18:31:50 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-07-13T18:31:50Z</dc:date>
    <item>
      <title>5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117751#M1071991</link>
      <description>&lt;P&gt;I'm pretty sure the answer to this is no, but I'd like to check just in case there's a workaround.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible for the management interface to be shared with the SFR module, so I can manage the ASA via SSH / ASDM via an IP on the management interface, and have the SFR configured and running on the same subnet?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 15:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117751#M1071991</guid>
      <dc:creator>richard.priest</dc:creator>
      <dc:date>2020-07-13T15:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: 5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117880#M1071994</link>
      <description>&lt;P&gt;Yes - that's the recommended design. Both the ASA and the sfr module share the physical management interface. They have different IP addresses on the same subnet. Think of them as VMs on the same host (rough analogy).&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 18:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117880#M1071994</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-13T18:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: 5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117884#M1071995</link>
      <description>&lt;P&gt;The ASA and SFR module share the management interface.&amp;nbsp; The IP subnet of both the ASA and SFR mgmt interface must be the same though.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;H3 class="p_H_Head3"&gt;ASA 5506-X (9.6 and Earlier) through ASA 5555-X (Software Module) in Routed Mode&lt;/H3&gt;
&lt;P class="pN1_Note1"&gt;&lt;A name="pgfId-152957" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="9" height="2" /&gt;&lt;/A&gt;: The ASA 5506-X and 5512-X do not support the FirePOWER module in 9.10 and later.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-152964" target="_blank"&gt;&lt;/A&gt;These models run the ASA FirePOWER module as a software module, and the ASA FirePOWER module shares the Management 0/0 or Management 1/1 interface (depending on your model) with the ASA.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-144843" target="_blank"&gt;&lt;/A&gt;All management traffic to and from the ASA FirePOWER module must enter and exit the Management interface. The ASA FirePOWER module also needs Internet access. Management traffic cannot pass through the ASA over the backplane; therefore you need to physically cable the management interface to an ASA interface to reach the Internet.&lt;/P&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-145520" target="_blank"&gt;&lt;/A&gt;If you do not configure a name and IP address in the ASA configuration for Management, then the interface belongs exclusively to the module. In this case, the Management interface is not a regular ASA interface, and you can:&lt;/P&gt;
&lt;P class="pNF_NumFirst"&gt;&lt;A name="pgfId-144890" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;1.&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="10" height="2" /&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Configure the ASA FirePOWER IP address to be on the same network as a regular ASA data interface.&lt;/P&gt;
&lt;P class="pNN_NumNext"&gt;&lt;A name="pgfId-144905" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;2.&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="10" height="2" /&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Specify the data interface as the ASA FirePOWER gateway.&lt;/P&gt;
&lt;P class="pNN_NumNext"&gt;&lt;A name="pgfId-144907" target="_blank"&gt;&lt;/A&gt;&lt;STRONG&gt;3.&lt;/STRONG&gt;&lt;A class="show-image-alone" title="blank.gif" href="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" target="_blank"&gt;&lt;IMG src="https://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" border="0" alt="blank.gif" width="10" height="2" /&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Directly connect the Management interface to the data interface (using a Layer2 switch).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/sfr/firepower-qsg.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2020 18:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4117884#M1071995</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-13T18:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: 5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4118182#M1072021</link>
      <description>&lt;P&gt;Thanks Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that's the recommended design why does all the documentation I've found / read imply that the two must be on separate interfaces?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5508X/asa-5508-5516-gsg/asa.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/5508X/asa-5508-5516-gsg/asa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5508-x.png" style="width: 975px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78933i0A764CB7CDE5DE1C/image-size/large?v=v2&amp;amp;px=999" role="button" title="5508-x.png" alt="5508-x.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5508-x_2.png" style="width: 621px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/78934i17055D957E3C993B/image-size/large?v=v2&amp;amp;px=999" role="button" title="5508-x_2.png" alt="5508-x_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Either way I'm happy I don't have to burn up an interface to utilise the SFR module.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 06:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4118182#M1072021</guid>
      <dc:creator>richard.priest</dc:creator>
      <dc:date>2020-07-14T06:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: 5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4118695#M1072046</link>
      <description>&lt;P&gt;What that document is stating is that you cannot set the management1/1 ASA IP to the same subnet that is already configured on the inside interface.&amp;nbsp; This is because the ASA will not allow two interfaces with an IP on the same subnet.&amp;nbsp; You can however set the same subnet on the FTD management1/1 interface as this is considered to be a seperate system from the ASA.&amp;nbsp; If you set a subnet for both the ASA and FTD management1/1 interface that is seperate from a subnet that already exists on the ASA system (and do routing on a L3 switch for example) then you can have an IP for both ASA and FTD management1/1 interface.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 19:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4118695#M1072046</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-07-14T19:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: 5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4118921#M1072057</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just so. +5 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 06:18:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4118921#M1072057</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-15T06:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: 5508-x &amp; SFR - mgmt interface</title>
      <link>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4119070#M1072062</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Superb, thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 10:28:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5508-x-amp-sfr-mgmt-interface/m-p/4119070#M1072062</guid>
      <dc:creator>richard.priest</dc:creator>
      <dc:date>2020-07-15T10:28:23Z</dc:date>
    </item>
  </channel>
</rss>

