<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 2110 ASA IMAGE- services using management interface not work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393831#M1080324</link>
    <description>&lt;P&gt;Ah OK - I see. Have you set the gateway for the FX-OS management so that it knows how to reach the NTP servers?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html#id_54695" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html#id_54695&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Apr 2021 09:02:49 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-04-27T09:02:49Z</dc:date>
    <item>
      <title>Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4392915#M1080286</link>
      <description>&lt;P&gt;Hi everyone! I am trying to use RADIUS,DNS and NTP Services using Management Interface from Firepower 2110 ASA image.&amp;nbsp; This interface has communication with the corporative network where the respective Servers reside.&amp;nbsp; Below the configurations from Firepower ASA:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.192.37.13 255.255.255.0 standby 10.192.37.14&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BRPRS1SECXFW003# sh route management-only&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Routing Table: mgmt-only&lt;BR /&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt;D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;E1 - OSPF external type 1, E2 - OSPF external type 2, V - VPN&lt;BR /&gt;i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt;ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt;o - ODR, P - periodic downloaded static route, + - replicated route&lt;BR /&gt;Gateway of last resort is 10.192.37.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;S* 0.0.0.0 0.0.0.0 [1/0] via 10.192.37.1, management&lt;BR /&gt;S 10.192.0.0 255.255.0.0 [1/0] via 10.192.37.1, management&lt;BR /&gt;C 10.192.37.0 255.255.255.0 is directly connected, management&lt;BR /&gt;L 10.192.37.13 255.255.255.255 is directly connected, management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Servers Address:&lt;/P&gt;&lt;P&gt;NTP/DNS - 10.192.0.30 and 31&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show dns&lt;BR /&gt;Domain Name Servers:&lt;BR /&gt;IP Address: 10.192.0.52 Order: 0&lt;BR /&gt;IP Address: 10.192.0.53 Order: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show ntp-server&lt;/P&gt;&lt;P&gt;NTP server hostname:&lt;BR /&gt;Name Time Sync Status&lt;BR /&gt;------------------------------ ----------------&lt;BR /&gt;10.192.0.52 Not Available&lt;BR /&gt;10.192.0.53 Not Available&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BRPRS1SECXFW003# show clock detail&lt;BR /&gt;21:47:29.539 UTC Sun Apr 25 2021&lt;BR /&gt;Time source is FXOS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show clock&lt;BR /&gt;Sun Apr 25 18:49:57 BRT 2021&lt;BR /&gt;firepower-2110 /system/services # show timezone&lt;BR /&gt;Timezone: America/Sao_Paulo&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show ntp-server detail&lt;/P&gt;&lt;P&gt;NTP server hostname:&lt;BR /&gt;Name: 10.192.0.52&lt;BR /&gt;Time Sync Status: Unreachable Or Invalid Ntp Server&lt;BR /&gt;Error Msg: The host is temporarily unreachable or may not be a NTP host. You may give more time to it or configure another one.&lt;/P&gt;&lt;P&gt;Name: 10.192.0.53&lt;BR /&gt;Time Sync Status: Unreachable Or Invalid Ntp Server&lt;BR /&gt;Error Msg: The host is temporarily unreachable or may not be a NTP host. You may give more time to it or configure another one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 22:04:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4392915#M1080286</guid>
      <dc:creator>GiovanniStavale53399</dc:creator>
      <dc:date>2021-04-25T22:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4392918#M1080287</link>
      <description>&lt;P&gt;A couple of things how is your configuration, what source use for NTP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ntp server&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;[ip address of NTP]&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;source&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;[interface name]&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another, is the NTP Server know how to reach back to ASA IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any ACL which allows NTP ? or any ACL which deny on the Management network?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 22:13:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4392918#M1080287</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-25T22:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393315#M1080302</link>
      <description>&lt;P&gt;Hi Balaji! thank you very much for your attention! We don´t have ACL on Management Interface 1/1 as you can see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BRPRS1SECXFW003# sh run access-group&lt;BR /&gt;access-group Outside_access_in in interface outside&lt;BR /&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # enter ntp-server 10.192.0.52&lt;BR /&gt;&amp;lt;CR&amp;gt;&lt;/P&gt;&lt;P&gt;The Firepower 2110 ASA image don´t have the option to assign the source interface on the ntp-server configuration as you can see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # enter ntp-server 10.192.0.52&lt;BR /&gt;&amp;lt;CR&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 15:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393315#M1080302</guid>
      <dc:creator>GiovanniStavale53399</dc:creator>
      <dc:date>2021-04-26T15:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393382#M1080304</link>
      <description>&lt;P&gt;Appologies you are right - i was referring traditionla ASa config :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is FXOS ASA config - you right :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now i will check the reachability to IP address using manangment interface&amp;nbsp; - 10.192.0.52 and did the NTP Server know routing back&amp;nbsp; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 16:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393382#M1080304</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-26T16:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393504#M1080309</link>
      <description>&lt;P&gt;Follow below the connectivity tests and Topology in attach.&amp;nbsp; We have connectivity from the Server to Firepower ASA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW-2# ping INT-FW2 10.192.37.13&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.192.37.13, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 80/86/90 ms&lt;/P&gt;&lt;P&gt;FW-1# ping INT-FW-1 10.192.37.13&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.192.37.13, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;FW-1# packet-tracer input FWPWR-IN udp 10.192.37.13 123 10.192.0.52 123&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: FLOW-EXPORT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 11&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 700190621, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: FWPWR-IN&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: FWPWR-OUT&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FWPR-2 xxxx udp 10.192.37.13 123 10.192.0.52 123&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: CAPTURE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in X.X.X.X 255.255.255.240&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in X.X.X.X 255.255.252.0&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 11&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 12&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 13&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 3640711285, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: FWPW-IN&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: FWPWR-OUT&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;BRPRS1SECXFW003# traceroute 10.192.0.52 source management&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 10.192.0.52&lt;/P&gt;&lt;P&gt;1 10.192.37.1 1 msec 1 msec 1 msec&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 19:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393504#M1080309</guid>
      <dc:creator>GiovanniStavale53399</dc:creator>
      <dc:date>2021-04-26T19:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393505#M1080310</link>
      <description>&lt;P&gt;You're moving back and forth between ASA cli and FXOS cli in your examples.&lt;/P&gt;
&lt;P&gt;If the chassis (prompt "firepower-2110 /system/services #") is synced to ntp it should provide that time to the ASA logical device.The chassis will only use the management interface.&lt;/P&gt;
&lt;P&gt;Alternatively, you have the option to independently sync the ASA (prompt "BRPRS1SECXFW003#") to the ntp servers. It's here that you can specify the source-interface.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 19:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393505#M1080310</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-26T19:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393547#M1080312</link>
      <description>&lt;P&gt;Hi Mr. Rhoads! Thank you for your attention!!&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We don´t have the option to configure ntp-server on ASA CLI with source interface as you can see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BRPRS1SECXFW003(config)# n?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;name names nat net&lt;BR /&gt;no nve&lt;/P&gt;&lt;P&gt;exec mode commands/options:&lt;BR /&gt;no&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The document that we´re using as a reference to configure that services is that Mr. Baladi posted here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to configure NTP/DNS and RADIUS services on Firepower 2110 with ASA IMAGE. This is the first time we have to configure it using this envinroment(Firepower + ASA Image)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seeing FXOS cli below, the NTP service isn´t sincronized with NTP servers 10.192.0.52 and .53 yet:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show ntp-server&lt;/P&gt;&lt;P&gt;NTP server hostname:&lt;BR /&gt;Name Time Sync Status&lt;BR /&gt;------------------------------ ----------------&lt;BR /&gt;10.192.0.52 Not Available&lt;BR /&gt;10.192.0.53 Not Available&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show ntp-server detail&lt;/P&gt;&lt;P&gt;NTP server hostname:&lt;BR /&gt;Name: 10.192.0.52&lt;BR /&gt;Time Sync Status: Unreachable Or Invalid Ntp Server&lt;BR /&gt;Error Msg: The host is temporarily unreachable or may not be a NTP host. You may give more time to it or configure another one.&lt;/P&gt;&lt;P&gt;Name: 10.192.0.53&lt;BR /&gt;Time Sync Status: Unreachable Or Invalid Ntp Server&lt;BR /&gt;Error Msg: The host is temporarily unreachable or may not be a NTP host. You may give more time to it or configure another one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a doubt about the management-only feature.. I am not sure that this option permit the routing InsidexOutside or that option consider just to permit the routing OutsidexInside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;interface Management1/1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;management-only&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nameif management&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security-level 100&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ip address 10.192.37.13 255.255.255.0 standby 10.192.37.14&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you know about this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 20:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393547#M1080312</guid>
      <dc:creator>GiovanniStavale53399</dc:creator>
      <dc:date>2021-04-26T20:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393831#M1080324</link>
      <description>&lt;P&gt;Ah OK - I see. Have you set the gateway for the FX-OS management so that it knows how to reach the NTP servers?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html#id_54695" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/fxos/config/asa-2100-fxos-config/cli.html#id_54695&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 09:02:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4393831#M1080324</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-27T09:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4394139#M1080331</link>
      <description>&lt;P&gt;Hi Mr Rhoads! We decided to keep the default configuration of the FXOS management interface, since the text below, informs that if we keep the default configuration, the FXOS sends the traffic through the backplane to the ASA data interfaces&lt;/P&gt;&lt;P&gt;Change the IP addresses or FXOS management gateway&lt;BR /&gt;You can change the FXOS management IP address on the FXOS CLI Firepower 2100 chassis. The default address is 192.168.45.45. You can also change the default gateway for FXOS management traffic. &lt;STRONG&gt;The default gateway is set to 0.0.0.0, which sends FXOS traffic over the backplane to be routed through the ASA data interfaces.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;I am not sure if our decision is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 15:48:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4394139#M1080331</guid>
      <dc:creator>GiovanniStavale53399</dc:creator>
      <dc:date>2021-04-27T15:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4395264#M1080383</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1187555"&gt;@GiovanniStavale53399&lt;/a&gt; I see. Have you checked the ASA data interface to see if the traffic for NTP synchronization is even leaving the box?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 07:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4395264#M1080383</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-04-29T07:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4399411#M1080607</link>
      <description>&lt;P&gt;I am in the process of deploying a Firepower 2120 with ASA image and platform mode so I had the opportunity to resolve this issue firsthand.&lt;/P&gt;
&lt;P&gt;I was able to get ntp to work by assigning a unique IP address to the fxos out-of-band interface (physically shared with the ASA management 1/1 interface on the chassis).&lt;/P&gt;
&lt;PRE&gt;firepower-2120 /fabric-interconnect # set out-of-band static ip &amp;lt;address&amp;gt; netmask 255.255.255.0 gw &amp;lt;gateway address&amp;gt;
Warning: When committed, this change may disconnect the current CLI session
 and dhcp server will be disabled.
Use commit-buffer command to commit the changes.
firepower-2120 /fabric-interconnect* # commit-buffer
&lt;/PRE&gt;
&lt;P&gt;Once I did this, NTP quickly synced and the correct time was passed to the ASA running on the appliance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;firepower-2120# show ntp-overall-status 

    NTP Overall Time-Sync Status: Time Synchronized
firepower-2120# scope system
firepower-2120 /system # scope services
firepower-2120 /system/services # show ntp-server detail

NTP server hostname:
    Name: time.nist.gov
    Time Sync Status: Time Synchronized
    Error Msg:
firepower-2120 /system/services # &lt;/PRE&gt;
&lt;P&gt;Be sure to have a valid DNS server configured if you are using FQDN(s) for the NTP server(s). Otherwise you can use IP addresses.&lt;/P&gt;
&lt;P&gt;The following may also be useful:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215468-configure-verify-and-troubleshoot-netwo.html#anc16" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215468-configure-verify-and-troubleshoot-netwo.html#anc16&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 15:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4399411#M1080607</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-05-07T15:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2110 ASA IMAGE- services using management interface not work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4399531#M1080616</link>
      <description>&lt;P&gt;Mr. Rhoads, thank you so much for your attention for this problem! You solved it!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We use an IP of the subnet 10.192.37.0/24, the same subnet of the ASA interface management as shown below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /fabric-interconnect # show config | in 10.192&lt;BR /&gt;set out-of-band static ip 10.192.37.15 netmask 255.255.255.0 gw 10.192.37.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that, the NTP service synchronized with NTP Server!&amp;nbsp; evidences below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system # sh ntp-overall-status&lt;/P&gt;&lt;P&gt;NTP Overall Time-Sync Status: Time Synchronized&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;firepower-2110 /system/services # show ntp-server detail&lt;/P&gt;&lt;P&gt;NTP server hostname:&lt;BR /&gt;Name: 10.192.36.50&lt;BR /&gt;Time Sync Status: Time Synchronized&lt;BR /&gt;Error Msg:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much Mr.Rhoads!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 20:29:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2110-asa-image-services-using-management-interface-not/m-p/4399531#M1080616</guid>
      <dc:creator>GiovanniStavale53399</dc:creator>
      <dc:date>2021-05-07T20:29:31Z</dc:date>
    </item>
  </channel>
</rss>

