<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC HA deployment and managed FTDs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296172#M1078733</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;4 FTDs in cluster HA Active/Passive should be added to 2 FMCs Active/Passive. FTDs are 4115.&lt;/P&gt;&lt;P&gt;I am perplexed on deployment of standby FMC, if it has to be aware of FTDs or not, I just now that passive FMC don't do any actions as long as active FMC is on line.&lt;/P&gt;&lt;P&gt;Should FTDs be configured to be managed by 2 managers (therefore 2 different IPs)? image below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104901iDD65BEBC891E0053/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or FTDs should be configured to be managed only by the active FMC? Image below&lt;/P&gt;&lt;P&gt;If that's the case, can standby FMC be unaware of FTDs, then active FMC will sink the standby?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104902i4E9DE009976960E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a virtual lab I couldn't configure 2 managers for the FTD, I received error message "&lt;STRONG&gt;This sensor is already managed"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Also since FMC has up 4 mgmt ports available, on the FMC is it wise to use a unique port "one IP" for doing everything (Managing FTDs + HA FMC)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Davide&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2021 16:16:58 GMT</pubDate>
    <dc:creator>DavideRanalli76560</dc:creator>
    <dc:date>2021-02-23T16:16:58Z</dc:date>
    <item>
      <title>FMC HA deployment and managed FTDs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296172#M1078733</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;4 FTDs in cluster HA Active/Passive should be added to 2 FMCs Active/Passive. FTDs are 4115.&lt;/P&gt;&lt;P&gt;I am perplexed on deployment of standby FMC, if it has to be aware of FTDs or not, I just now that passive FMC don't do any actions as long as active FMC is on line.&lt;/P&gt;&lt;P&gt;Should FTDs be configured to be managed by 2 managers (therefore 2 different IPs)? image below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104901iDD65BEBC891E0053/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or FTDs should be configured to be managed only by the active FMC? Image below&lt;/P&gt;&lt;P&gt;If that's the case, can standby FMC be unaware of FTDs, then active FMC will sink the standby?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104902i4E9DE009976960E5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.PNG" alt="2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a virtual lab I couldn't configure 2 managers for the FTD, I received error message "&lt;STRONG&gt;This sensor is already managed"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Also since FMC has up 4 mgmt ports available, on the FMC is it wise to use a unique port "one IP" for doing everything (Managing FTDs + HA FMC)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Davide&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 16:16:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296172#M1078733</guid>
      <dc:creator>DavideRanalli76560</dc:creator>
      <dc:date>2021-02-23T16:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: FMC HA deployment and managed FTDs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296217#M1078737</link>
      <description>&lt;P&gt;Check out this excellent blog on the subject: &lt;A href="https://dependencyhell.net/2017-07-10-fmc-ha/" target="_blank"&gt;https://dependencyhell.net/2017-07-10-fmc-ha/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Essentially the FTDs will only be registered to the active FMC but they send events to both the active and standby FMC. The active FMC syncs with the standby FMC so the standby can take over in the event that the primary FMC fails.&lt;/P&gt;&lt;P&gt;As for using multiple interfaces, that depends on how much traffic is being utilized on those links. Unless you have an extra NIC in your server, the interfaces are usually:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CIMC interface (labeled "M")&lt;/LI&gt;&lt;LI&gt;Serial console port&lt;/LI&gt;&lt;LI&gt;eth0 (labeled "1")&lt;/LI&gt;&lt;LI&gt;eth1 (labeled "2")&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;That means you really only have 2 x 1-Gbps interfaces to work with and you could change one of those interfaces to be the "events only" interface. If you have an additional NIC, you gain two additional 10-Gbps interfaces.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fmc-1600-2600-4600/hw/guide/install-fmc-1600-2600-4600/overview.html#concept_otx_2ld_4db" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fmc-1600-2600-4600/hw/guide/install-fmc-1600-2600-4600/overview.html#concept_otx_2ld_4db&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 17:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296217#M1078737</guid>
      <dc:creator>TJ-20933766</dc:creator>
      <dc:date>2021-02-23T17:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: FMC HA deployment and managed FTDs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296306#M1078744</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks very much Joachims, regarding the 4 interfaces:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CIMC interface (labeled "M")&lt;/LI&gt;&lt;LI&gt;Serial console port&lt;/LI&gt;&lt;LI&gt;eth0 (labeled "1")&lt;/LI&gt;&lt;LI&gt;eth1 (labeled "2")&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;would the CIMC be the equivalent of OOB (Out Of Band) Interface, whereas&amp;nbsp;eth0 and&amp;nbsp;eth1 are for HA, mgmt and so on?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 19:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296306#M1078744</guid>
      <dc:creator>DavideRanalli76560</dc:creator>
      <dc:date>2021-02-23T19:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: FMC HA deployment and managed FTDs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296316#M1078746</link>
      <description>&lt;P&gt;The CIMC is for management of the hardware of the server. Status of the RAID controller, hard drive health, fan health, alerts, and so on are found here. You can also use the CIMC to get KVM access to the server. If you have not set it up, you can do so by either:&lt;/P&gt;&lt;P&gt;1. Rebooting the server and entering the CIMC configuration menu (F8 I believe)&lt;/P&gt;&lt;P&gt;2. Connect the CIMC interface to a network that has a DHCP server and web browse to the IP address that the CIMC gets from DHCP. Default credentials are admin / Cisco1234 but if those don't work, you'll have to resort to option 1.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 19:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296316#M1078746</guid>
      <dc:creator>TJ-20933766</dc:creator>
      <dc:date>2021-02-23T19:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: FMC HA deployment and managed FTDs</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296470#M1078753</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Very much appreciated Joachims, thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Davide&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 21:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ha-deployment-and-managed-ftds/m-p/4296470#M1078753</guid>
      <dc:creator>DavideRanalli76560</dc:creator>
      <dc:date>2021-02-23T21:45:57Z</dc:date>
    </item>
  </channel>
</rss>

