<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access FTD management Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161117#M1074388</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the FTD is default gateway for the Inside network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I would need a static route on the FTD pointing to the switch?&lt;/P&gt;&lt;P&gt;It looks like I cannot add a route using the management interface on the FTD or do you mean I should add a route using the FTD Inside interface pointing to the switch?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;/Chess&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 03 Oct 2020 19:12:55 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2020-10-03T19:12:55Z</dc:date>
    <item>
      <title>Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161112#M1074386</link>
      <description>&lt;P&gt;In my lab, I previously had my FTD management interface on the same subnet as my inside network. The inside network is using the FTD Inside interface as gateway and everything was working without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recently created a separate management network and configured a VLAN interface (SVI)on my 3560 switch and reconfigured the FTD management interface with an IP address on this network and using the management SVI as gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I now have have an issue reaching the management interface on the FTD from the Inside network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I create an additional sub interface on the FTD on the same management network I can reach the FTD, but is this really necessary?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would appreciate some guidelines on how to configure the FTD, so that I can access the management&amp;nbsp; from my inside network.&lt;/P&gt;&lt;P&gt;Inside network is 10.46.1.0/24 and management network is 172.16.1.0/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;/Chess&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 19:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161112#M1074386</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2020-10-03T19:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161113#M1074387</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the default gateway of devices connected to the inside network, the FTD or the switch itself? If it's the FTD, that would need a route to the management network to route the traffic back to the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 18:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161113#M1074387</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-03T18:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161117#M1074388</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes the FTD is default gateway for the Inside network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I would need a static route on the FTD pointing to the switch?&lt;/P&gt;&lt;P&gt;It looks like I cannot add a route using the management interface on the FTD or do you mean I should add a route using the FTD Inside interface pointing to the switch?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;/Chess&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 19:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161117#M1074388</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2020-10-03T19:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161118#M1074389</link>
      <description>&lt;P&gt;Traffic is sourced from the inside network would be routed to the FTD's inside interface and would need to be routed back via the FTD's inside interface to the SVI, which (if ip routing is enabled) would route the traffic to the management interface. That's not great from a routing point of view, but it will work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 19:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161118#M1074389</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-03T19:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161126#M1074391</link>
      <description>&lt;P&gt;Really appreciate the help, but something still isn't working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Here's the configuration so far:&lt;BR /&gt;Inside network: 10.46.0.0/24&lt;BR /&gt;Management Network: 172.16.1.0/24&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Switch configuration:&lt;BR /&gt;!&lt;BR /&gt;ip routing&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;description ***INSIDE***&lt;BR /&gt;ip address 10.46.0.16 255.255.255.0&lt;BR /&gt;no ip mroute-cache&lt;BR /&gt;!&lt;BR /&gt;interface Vlan13&lt;BR /&gt;description ***MGMT***&lt;BR /&gt;ip address 172.16.1.1 255.255.255.0&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip mroute-cache&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;description ***FTD-01 (MGMT)***&lt;BR /&gt;switchport access vlan 13&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast edge&lt;BR /&gt;!&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 10.46.0.1&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;FTD config&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==================[ management0 ]===================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Link : Up&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode : Non-Autonegotiation&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 5C:5A:C7:CF:66:80&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 172.16.1.10&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Gateway : 172.16.1.1&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;BR /&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;nameif INSIDE&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 10.46.0.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;route INSIDE 172.16.1.0 255.255.255.0 10.46.0.16 1&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Thanks&lt;BR /&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 20:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161126#M1074391</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2020-10-03T20:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161127#M1074392</link>
      <description>&lt;P&gt;As the traffic is being routed to the firewall you will need to ensure you are permitting the traffic, have you permitted traffic from 10.46.0.0 to 172.16.1.0? Troubleshoot using "system firewall-engine-debug"&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 20:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161127#M1074392</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-10-03T20:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FTD management Interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161132#M1074393</link>
      <description>&lt;P&gt;Thanks, It was the zones in the ACP that was wrong. Since the traffic both enter and exit the inside, I needed to use the inside zone as both source and destination.&lt;/P&gt;&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Sat, 03 Oct 2020 21:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-ftd-management-interface/m-p/4161132#M1074393</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2020-10-03T21:21:30Z</dc:date>
    </item>
  </channel>
</rss>

