<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD management over Internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497624#M1084815</link>
    <description>&lt;P&gt;Ah, I might have forgotten that piece of information. My management interfaces have public IPs.&lt;/P&gt;&lt;P&gt;I found the CLI settings&amp;nbsp;ssh-access-list and https-access-list which seems to do the trick for SSH access but what about SNMP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
    <pubDate>Thu, 04 Nov 2021 06:06:04 GMT</pubDate>
    <dc:creator>hoffa2000</dc:creator>
    <dc:date>2021-11-04T06:06:04Z</dc:date>
    <item>
      <title>FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497094#M1084797</link>
      <description>&lt;P&gt;Greetings&lt;/P&gt;&lt;P&gt;I have a scenario where my FTDs are only reachable for management by the FMC over Internet. The FTDs are running HA so data interface access isn't an option. I assume data in transit is properly encrypted but how do I secure access to the FTD management interface? I have yet to find an ACL option for the actual management interface, I'm thinking about using black-hole routing but it seems kind of cheap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Fredrik&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 11:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497094#M1084797</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2021-11-03T11:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497099#M1084798</link>
      <description>&lt;P&gt;i would put management in different VLAN, Do NAT on Internet Router with Public to Private IP, if you know FMC Public IP, then&amp;nbsp; i will restrict with ACL to allow only FMC IP contacting FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since if&amp;nbsp; you do not have option to deploy Lan, if you have only option to communicate from External Internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 11:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497099#M1084798</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-03T11:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497367#M1084810</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thank you for the answer. As I don't have any control over our Internet router I'd like to look into the ACL option. How is that done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 18:06:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497367#M1084810</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2021-11-03T18:06:54Z</dc:date>
    </item>
    <item>
      <title>Re: FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497460#M1084812</link>
      <description>&lt;P&gt;if the Internet&amp;nbsp; Router does not do NAT, then how will an external connection establish to FTD, that fails - since Manangment is RFC1918 address (that was my impression)&amp;nbsp; or Do&amp;nbsp; you have Public IP configured on Manangment?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 19:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497460#M1084812</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-03T19:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497624#M1084815</link>
      <description>&lt;P&gt;Ah, I might have forgotten that piece of information. My management interfaces have public IPs.&lt;/P&gt;&lt;P&gt;I found the CLI settings&amp;nbsp;ssh-access-list and https-access-list which seems to do the trick for SSH access but what about SNMP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 06:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497624#M1084815</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2021-11-04T06:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497719#M1084818</link>
      <description>&lt;P&gt;Why do you need SNMP over Public? if you are intent to use try SNMPv3, also the same ACP rule you can apply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 09:22:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4497719#M1084818</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-04T09:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD management over Internet</title>
      <link>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4501941#M1085036</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I don't that's the thing. I ONLY want FMC management on my Internet connected management interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Fredrik&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 10:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-management-over-internet/m-p/4501941#M1085036</guid>
      <dc:creator>hoffa2000</dc:creator>
      <dc:date>2021-11-12T10:23:04Z</dc:date>
    </item>
  </channel>
</rss>

