<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up FTD on 4110: Management and failover interfaces setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422273#M1081712</link>
    <description>&lt;P&gt;1) You will need to use an interface from the network module as a mgmt interface for communication with FMC/using it for mgmt as FDM. 6.7 does have a feature to use data interface for mgmt, but it can be used only for standalone units and not for HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) You can use an unused, but enabled, data interface (physical) as the failover link; however, you cannot specify an interface that is currently configured with a name. The failover link interface is not configured as a normal networking interface; it exists for failover communication only. This interface can only be used for the failover link (and also for the state link). &lt;STRONG&gt;You cannot use a management interface&lt;SPAN class="ph"&gt; or a &lt;/SPAN&gt;subinterface for failover.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Source: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-ha.html#concept_ud1_j2b_d3b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-ha.html#concept_ud1_j2b_d3b&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chakshu&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts !&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jun 2021 06:55:48 GMT</pubDate>
    <dc:creator>Chakshu Piplani</dc:creator>
    <dc:date>2021-06-23T06:55:48Z</dc:date>
    <item>
      <title>Setting up FTD on 4110: Management and failover interfaces setup</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422114#M1081710</link>
      <description>&lt;P&gt;We are in the process of deploying an FTD on a 4110. We have access to the web interface of the firewall chassis manager and the fxos via ssh. I uploaded FTD-6.6.4 onto the appliance, and I'm trying to create a logical FTD device. There is the one management interface and four 10Gbps interfaces. I've selected Native instance type and Standalone usage. Here is what I can't figure out as I read through the Cisco documentation:&lt;/P&gt;&lt;P&gt;1) The management interfaces for FCM doesn't appear to be usable by the FTD, but there is no way I want to use a 10 Gbps interface. Is there a way to use the management interface for the chassis? There isn't an option to select this when creating a logical device.&lt;/P&gt;&lt;P&gt;2) We're wanting to use HA, but again I don't want to use a dedicated 10 Gbps module for failover and stateful. Is it possible to use a subinterface of one of the data interfaces?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 20:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422114#M1081710</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2021-06-22T20:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up FTD on 4110: Management and failover interfaces setup</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422273#M1081712</link>
      <description>&lt;P&gt;1) You will need to use an interface from the network module as a mgmt interface for communication with FMC/using it for mgmt as FDM. 6.7 does have a feature to use data interface for mgmt, but it can be used only for standalone units and not for HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) You can use an unused, but enabled, data interface (physical) as the failover link; however, you cannot specify an interface that is currently configured with a name. The failover link interface is not configured as a normal networking interface; it exists for failover communication only. This interface can only be used for the failover link (and also for the state link). &lt;STRONG&gt;You cannot use a management interface&lt;SPAN class="ph"&gt; or a &lt;/SPAN&gt;subinterface for failover.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Source: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-ha.html#concept_ud1_j2b_d3b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-ha.html#concept_ud1_j2b_d3b&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Chakshu&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts !&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 06:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422273#M1081712</guid>
      <dc:creator>Chakshu Piplani</dc:creator>
      <dc:date>2021-06-23T06:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up FTD on 4110: Management and failover interfaces setup</title>
      <link>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422334#M1081719</link>
      <description>&lt;P&gt;Like &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/249271"&gt;@Chakshu Piplani&lt;/a&gt; noted, you always have to allocate at least two of the physical data interfaces on a 4100 series (or 9300 series) HA pair:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;(1) FTD management and&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;(2) failover&lt;/P&gt;
&lt;P&gt;The "GE Mgmt" interface is only for chassis management. While you can get to the ftd cli through it, it requires some commands post-login and thus is not generally usable for system operations - only for manual troubleshooting in a pinch.&lt;/P&gt;
&lt;P&gt;That's true up through the (current) latest 7.0 release.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 08:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/setting-up-ftd-on-4110-management-and-failover-interfaces-setup/m-p/4422334#M1081719</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-23T08:28:04Z</dc:date>
    </item>
  </channel>
</rss>

