<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Management interface for logical FTD on Firepower 4100 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4307000#M1079264</link>
    <description>&lt;P&gt;While we note that the documentation for Firepower 6.7 says that you can "manage the FTD using a data interface instead of the Management interface", I know that, at least through the latest FXOS for a 4100 or 9300 series, you cannot deploy an FTD logical device without first designating one of the network interfaces as exclusively management (not data). Note that the guide tells us explicitly:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;"You can later enable management from a data interface; but you must assign a Management interface to the logical device even if you don't intend to use it after you enable data management. See &lt;SPAN class="ph"&gt;the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure network management-data-interface&lt;/SPAN&gt; &lt;/SPAN&gt; command in the &lt;A class="xref" href="https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense.html" target="_blank" rel="noopener"&gt;FTD command reference&lt;/A&gt;&lt;/SPAN&gt; for more information."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Reference: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos291/web-guide/b_GUI_FXOS_ConfigGuide_291/logical_devices.html#task_4D51AFC7091E4D8F8289F08C6A071459" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos291/web-guide/b_GUI_FXOS_ConfigGuide_291/logical_devices.html#task_4D51AFC7091E4D8F8289F08C6A071459&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 14 Mar 2021 10:15:35 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-03-14T10:15:35Z</dc:date>
    <item>
      <title>Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4306456#M1079250</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll shortly have to deploy a physical firepower of the 4100 family "4115".&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that the first MGMT interface showing up is for chassis FXOS purpuses. In Cisco videos I've seen that the management interface used for FTD "logical instance" is the ethernet1/1 .&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FTD.PNG" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/106272i36765609269C5E90/image-size/medium?v=v2&amp;amp;px=400" role="button" title="FTD.PNG" alt="FTD.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1) I am right on saying that management interface for FTD can be any of the interfaces available on the fixed module?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) On FTD can I use a subinterface as management (and FMC use that same subinterface), or management interface must be physical?&lt;/P&gt;&lt;P&gt;3) Management interface on FTD, can also work as data interface? (for example as mgmt interface i use the once facing as server in a DMZ)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately on my virtual lab I couldn't test these things&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advanced&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 18:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4306456#M1079250</guid>
      <dc:creator>DavideRanalli97851</dc:creator>
      <dc:date>2021-03-12T18:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4306737#M1079253</link>
      <description>&lt;P&gt;Yes - you must use a separate dedicated physical interface for management. Firepower Chassis Manager will not allow you do deploy an FTD logical devices without having that configured and available.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Mar 2021 12:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4306737#M1079253</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-03-13T12:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4306974#M1079262</link>
      <description>&lt;P&gt;Thanks Marvin,&lt;/P&gt;&lt;P&gt;so i must first define a management interface, for example eth1/1, then I can create the FTD logical device and apply eth1/1 to it, but can that eth1/1 interface be used for both data and management or does it have to be used exclusively for managemet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 07:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4306974#M1079262</guid>
      <dc:creator>DavideRanalli97851</dc:creator>
      <dc:date>2021-03-14T07:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4307000#M1079264</link>
      <description>&lt;P&gt;While we note that the documentation for Firepower 6.7 says that you can "manage the FTD using a data interface instead of the Management interface", I know that, at least through the latest FXOS for a 4100 or 9300 series, you cannot deploy an FTD logical device without first designating one of the network interfaces as exclusively management (not data). Note that the guide tells us explicitly:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;"You can later enable management from a data interface; but you must assign a Management interface to the logical device even if you don't intend to use it after you enable data management. See &lt;SPAN class="ph"&gt;the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure network management-data-interface&lt;/SPAN&gt; &lt;/SPAN&gt; command in the &lt;A class="xref" href="https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense.html" target="_blank" rel="noopener"&gt;FTD command reference&lt;/A&gt;&lt;/SPAN&gt; for more information."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Reference: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos291/web-guide/b_GUI_FXOS_ConfigGuide_291/logical_devices.html#task_4D51AFC7091E4D8F8289F08C6A071459" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/fxos/fxos291/web-guide/b_GUI_FXOS_ConfigGuide_291/logical_devices.html#task_4D51AFC7091E4D8F8289F08C6A071459&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 10:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4307000#M1079264</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-03-14T10:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4307117#M1079285</link>
      <description>&lt;P&gt;Fantastic thanks Marvin, you couldn't be clearer than this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 19:32:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/4307117#M1079285</guid>
      <dc:creator>DavideRanalli97851</dc:creator>
      <dc:date>2021-03-14T19:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360073#M1124047</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="39" data-end="193"&gt;&lt;STRONG data-start="39" data-end="101"&gt;Does the management interface have to be connected or not?&lt;/STRONG&gt;&lt;BR data-start="101" data-end="104" /&gt;Because I am trying to add the &lt;STRONG data-start="135" data-end="142"&gt;FTD&lt;/STRONG&gt; inside &lt;STRONG data-start="150" data-end="158"&gt;FXOS&lt;/STRONG&gt;, but when I enter the CLI and run:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="sticky top-[calc(--spacing(9)+var(--header-height))] @w-xl/main:top-9"&gt;
&lt;DIV class="absolute end-0 bottom-0 flex h-9 items-center pe-2"&gt;
&lt;DIV class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN&gt;&lt;SPAN class="hljs-keyword"&gt;show&lt;/SPAN&gt; managers
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-start="195" data-end="216"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-start="218" data-end="254" data-is-last-node="" data-is-only-node=""&gt;the device keeps doing a &lt;STRONG data-start="243" data-end="253"&gt;reload&lt;/STRONG&gt;.&amp;nbsp;&lt;BR /&gt;and the dashboard for FXOS , the Roman version is exciting also , is normal&amp;nbsp;&lt;BR /&gt;4100&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 21:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360073#M1124047</guid>
      <dc:creator>m-abutaleb</dc:creator>
      <dc:date>2026-01-08T21:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360269#M1124061</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1799628"&gt;@m-abutaleb&lt;/a&gt;&amp;nbsp;please create a new discussion and provide more details on your specific situation. The thread you are replying to is almost 5 years old.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2026 15:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360269#M1124061</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-01-09T15:45:12Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360337#M1124067</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="64" data-end="97"&gt;I will explain my question again.&lt;/P&gt;
&lt;P data-start="99" data-end="391"&gt;I am trying to add an &lt;STRONG data-start="121" data-end="133"&gt;FTD 4100&lt;/STRONG&gt; to &lt;STRONG data-start="137" data-end="145"&gt;FXOS&lt;/STRONG&gt;, but I am only connected &lt;STRONG data-start="171" data-end="210"&gt;back-to-back on the management port&lt;/STRONG&gt;, and I did &lt;STRONG data-start="222" data-end="288"&gt;not connect the interface that should be dedicated for the FTD&lt;/STRONG&gt;.&lt;BR data-start="289" data-end="292" /&gt;I configured that interface type as &lt;STRONG data-start="328" data-end="342"&gt;Management&lt;/STRONG&gt;, but it is &lt;STRONG data-start="354" data-end="390"&gt;not connected to the core switch&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="393" data-end="414"&gt;So when I try to run:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="sticky top-[calc(--spacing(9)+var(--header-height))] @w-xl/main:top-9"&gt;
&lt;DIV class="absolute end-0 bottom-0 flex h-9 items-center pe-2"&gt;
&lt;DIV class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN&gt;connect &lt;SPAN class="hljs-keyword"&gt;module&lt;/SPAN&gt; &lt;SPAN class="hljs-number"&gt;1&lt;/SPAN&gt; console
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;PRE class="overflow-visible! px-0!" data-start="416" data-end="448"&gt;&amp;nbsp;&lt;/PRE&gt;
&lt;P data-start="450" data-end="500"&gt;from FXOS to connect to the FTD, I cannot connect.&lt;/P&gt;
&lt;P data-start="502" data-end="621"&gt;My question is:&lt;BR data-start="517" data-end="520" /&gt;&lt;STRONG data-start="520" data-end="621"&gt;Does the FTD Management port have to be physically connected to the core switch for this to work?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jan 2026 18:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360337#M1124067</guid>
      <dc:creator>m-abutaleb</dc:creator>
      <dc:date>2026-01-09T18:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Management interface for logical FTD on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360587#M1124073</link>
      <description>&lt;P&gt;No it does not need to be physically connected to anything for it to initialize. However you may have done other things during your testing that would cause it to fail. It's hard to say what given the limited information you have provided. Generally, the document you would follow for reimaging FTD is this one:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/2100/troubleshoot_fxos/b_2100_CLI_Troubleshoot/b_2100_CLI_Troubleshoot_chapter_011.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/2100/troubleshoot_fxos/b_2100_CLI_Troubleshoot/b_2100_CLI_Troubleshoot_chapter_011.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 14:32:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-for-logical-ftd-on-firepower-4100/m-p/5360587#M1124073</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2026-01-12T14:32:53Z</dc:date>
    </item>
  </channel>
</rss>

