<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA&amp;gt;FTD mgmt in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148221#M1073715</link>
    <description>&lt;P&gt;If you are using FMC to manage the FTD then you don't connect to it directly on https. You now need to configure it using the FMC.&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2020 07:16:57 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-09-09T07:16:57Z</dc:date>
    <item>
      <title>Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148185#M1073711</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;We recently re-imaged 5516-x to FTD.&lt;/P&gt;&lt;P&gt;I am not able to access it using IP assigned to mgmt ip&lt;/P&gt;&lt;P&gt;When I do "show network"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : testftd&lt;BR /&gt;Management port : 8305&lt;BR /&gt;IPv4 Default route&lt;BR /&gt;Gateway : 10.10.0.1&lt;/P&gt;&lt;P&gt;======================[ br1 ]=======================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode : Non-Autonegotiation&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 03:AB:C4:C7:70:96&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 10.10.0.60&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Broadcast : 10.10.0.255&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;&lt;P&gt;When I ping 10.10.0.60 or 10.10.0.1 it says&amp;nbsp;&lt;/P&gt;&lt;P&gt;No route to host X.X.X.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I checked in LINA engine Mgmt1/1 interface is admin down.&lt;/P&gt;&lt;P&gt;I selected option to manage it locally while setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I access it ?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 05:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148185#M1073711</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-09T05:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148197#M1073712</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Use the command "ping&lt;STRONG&gt; system &lt;/STRONG&gt;10.10.0.60"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 06:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148197#M1073712</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-09T06:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148210#M1073713</link>
      <description>&lt;P&gt;Hello Rob,&lt;/P&gt;&lt;P&gt;It's pinging. But from outside I am not able to access that IP using https.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 07:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148210#M1073713</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-09T07:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148221#M1073715</link>
      <description>&lt;P&gt;If you are using FMC to manage the FTD then you don't connect to it directly on https. You now need to configure it using the FMC.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 07:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148221#M1073715</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-09T07:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148226#M1073717</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am not using FMC, I am planning to administer it locally only using FDM.&lt;/P&gt;&lt;P&gt;Also I tried ping to gateway "ping system 10.10.0.1" and it's not pinging. Switch port config is good I double checked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 07:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148226#M1073717</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-09T07:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148228#M1073718</link>
      <description>&lt;P&gt;Sorry, my mistake, for some reason I thought you were using and FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you attempted to connect to the FTD using https from a PC in the same VLAN?&lt;/P&gt;
&lt;P&gt;To answer your previous question, you wouldn't be able to access the FTD from the outside, because until you've configured the FTD there is no outside interface, only the mgmt interface.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 07:36:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148228#M1073718</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-09-09T07:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148322#M1073725</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/212135"&gt;@umeshunited&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connetct your laptop directly to the firewall in case you think that something is not right with your internal network, your should be able to SSH to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But give reboot before you try it.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 10:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148322#M1073725</guid>
      <dc:creator>Ruben Cocheno</dc:creator>
      <dc:date>2020-09-09T10:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148336#M1073730</link>
      <description>&lt;P&gt;Unfortunately I do not have any PC in that LAN right now. I am trying to ping 10.10.0.60 from switch( to which it's mgmt is connected) but not able to ping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If gateway is correct than I should be able to ping gateway and any device should be able to ping it.&lt;/P&gt;&lt;P&gt;I am trying to https it via mgmt IP from different subnet but no luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 11:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4148336#M1073730</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-09T11:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4149752#M1073836</link>
      <description>&lt;P&gt;I have connected laptop to inside interface. I can ping it but not https/ssh.&lt;/P&gt;&lt;P&gt;Moreover I see some cts config already present on it apart from&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;cts manual&lt;BR /&gt;propagate sgt preserve-untag&lt;BR /&gt;policy static sgt disabled trusted&lt;BR /&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;Do I need to enable something from ftd?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 14:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4149752#M1073836</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-11T14:47:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4149768#M1073837</link>
      <description>&lt;P&gt;I have connected laptop to inside interface. I can ping it but not https/ssh.&lt;/P&gt;&lt;P&gt;Moreover I see some cts config already present on it apart from&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;cts manual&lt;BR /&gt;propagate sgt preserve-untag&lt;BR /&gt;policy static sgt disabled trusted&lt;BR /&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;Do I need to enable something from ftd?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 14:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4149768#M1073837</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-11T14:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4149831#M1073842</link>
      <description>&lt;P&gt;I also tried adding network in "configure https-access-list...." and "configure ssh-access-list .... " but no luck.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 17:17:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4149831#M1073842</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-11T17:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA&gt;FTD mgmt</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4152210#M1073960</link>
      <description>&lt;P&gt;So here what helped me get access.&lt;/P&gt;&lt;P&gt;Configuration register was set as 0x41 so it was not loading default FTD configuration so mgmt interface was showing in admin down state. We changed it to 0x01 from ROMMON mode and now I was able to access it using mgmt interface IP address.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2020 17:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-gt-ftd-mgmt/m-p/4152210#M1073960</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2020-09-16T17:15:28Z</dc:date>
    </item>
  </channel>
</rss>

