<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco FTD 6.6.1 - VPN management access problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4188718#M1076122</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I have FTD 6.6.1 with FDM, I configured Remote Access VPN, and everythink working good&amp;nbsp;except for management FTD.&lt;/P&gt;&lt;P&gt;I would like to be able to manage this device after VPN connection. I configured one of data interfaces as a MGMT:&lt;/P&gt;&lt;P&gt;ftd1l# show nameif&lt;BR /&gt;Interface Name Security&lt;BR /&gt;Ethernet1/2.4 mgmt 0&lt;BR /&gt;Ethernet1/2.4 192.168.4.1&lt;/P&gt;&lt;P&gt;I configured management-access command via FlexConfig&lt;/P&gt;&lt;P&gt;ftd1l# sh run | i management&lt;BR /&gt;management-access mgmt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ftd1# sh run ssh&lt;BR /&gt;ssh 192.168.7.0 255.255.255.0 mgmt&lt;BR /&gt;ftd1# sh run http&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.7.0 255.255.255.0 mgmt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (mgmt,outside) source static 192.168.4.0&amp;nbsp;192.168.4.0 destination static vpnpool vpnpool no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I still can't access to FTD....&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also SW on this subnet 192.168.4.0 with IP 192.168.4.200 and I able to connect it via SSH...&lt;/P&gt;&lt;P&gt;What is wrong on FTD ?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2020 14:23:07 GMT</pubDate>
    <dc:creator>mikiNet</dc:creator>
    <dc:date>2020-11-25T14:23:07Z</dc:date>
    <item>
      <title>Cisco FTD 6.6.1 - VPN management access problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4188718#M1076122</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I have FTD 6.6.1 with FDM, I configured Remote Access VPN, and everythink working good&amp;nbsp;except for management FTD.&lt;/P&gt;&lt;P&gt;I would like to be able to manage this device after VPN connection. I configured one of data interfaces as a MGMT:&lt;/P&gt;&lt;P&gt;ftd1l# show nameif&lt;BR /&gt;Interface Name Security&lt;BR /&gt;Ethernet1/2.4 mgmt 0&lt;BR /&gt;Ethernet1/2.4 192.168.4.1&lt;/P&gt;&lt;P&gt;I configured management-access command via FlexConfig&lt;/P&gt;&lt;P&gt;ftd1l# sh run | i management&lt;BR /&gt;management-access mgmt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ftd1# sh run ssh&lt;BR /&gt;ssh 192.168.7.0 255.255.255.0 mgmt&lt;BR /&gt;ftd1# sh run http&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.7.0 255.255.255.0 mgmt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat (mgmt,outside) source static 192.168.4.0&amp;nbsp;192.168.4.0 destination static vpnpool vpnpool no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I still can't access to FTD....&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have also SW on this subnet 192.168.4.0 with IP 192.168.4.200 and I able to connect it via SSH...&lt;/P&gt;&lt;P&gt;What is wrong on FTD ?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 14:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4188718#M1076122</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2020-11-25T14:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 6.6.1 - VPN management access problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4189230#M1076147</link>
      <description>&lt;P&gt;Is the VPN configured to either be full tunnel or, if split tunnel. include the management subnet?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 12:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4189230#M1076147</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-11-26T12:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 6.6.1 - VPN management access problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4189250#M1076153</link>
      <description>&lt;P&gt;Split tunnel include the management subnet. As I mentioned, any other device in management subnet are accesible via VPN&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 18:20:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4189250#M1076153</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2020-11-26T18:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 6.6.1 - VPN management access problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4190751#M1076272</link>
      <description>&lt;P&gt;This is a BUG in software FDM &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below answer from Cisco Engineer:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I have check internally and found that unfortunately it's still not supported to enable manage the device through AnyConnect to the inside interface, there is already a bug has been opened to address this issue:&lt;/P&gt;&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt73926" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt73926&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer the below workarounds:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Connect and internal computer/server then access the FTD, and this computer/server needs to be added to the encryption domain for the VPN tunnel (such as when we SSH the FTD from the internal switch).&lt;/LI&gt;&lt;LI&gt;Manage the FDM through the outside interface. SSH/SNMP/HTTPS will be done through the outside interface.&lt;/LI&gt;&lt;LI&gt;you might consider using FMC to manage the FTD, as FMC has more options and more flexibility to manage the FTD since it's considered a separate device.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 30 Nov 2020 13:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4190751#M1076272</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2020-11-30T13:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 6.6.1 - VPN management access problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4190758#M1076274</link>
      <description>&lt;P&gt;Good info. Thanks for sharing the BugID.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 13:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4190758#M1076274</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-11-30T13:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco FTD 6.6.1 - VPN management access problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4785938#M1098298</link>
      <description>&lt;P&gt;A BUG which is still not fixed yet... interesting. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 13:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-ftd-6-6-1-vpn-management-access-problem/m-p/4785938#M1098298</guid>
      <dc:creator>Alex Ziegelschmied</dc:creator>
      <dc:date>2023-03-02T13:26:27Z</dc:date>
    </item>
  </channel>
</rss>

