<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help disabling FTD HA Encryption in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526729#M1086178</link>
    <description>&lt;P&gt;As you've surmised, "the only way to disable the encryption is by deleting the HA group from FMC GUI and create a new one with encryption disabled".&lt;/P&gt;
&lt;P&gt;There's no cli-based method and it will be a disruptive change. That said, it is otherwise relatively straightforward&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jan 2022 07:35:35 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2022-01-05T07:35:35Z</dc:date>
    <item>
      <title>Help disabling FTD HA Encryption</title>
      <link>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526597#M1086176</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;I moved to a new job couple months ago, and they are using CISCO FTD's. I am a PaloAlto guy and still learning about FTDs, and to be honest I am not a big fan of FTDs as they are not flexible and stable as Palos. Anyways, whoever built those FTDs they configured IPsec encryption on the HA link, and of course there is a bug causing FWs to get out of Sync due to the encryption on the HA link and the only way to fix the issue is to remove the encryption. I am using FMC to mange those FTDs. From reading about FTD HA configuration, seems the only way to disable the encryption is by deleting the HA group from FMC GUI and create a new one with encryption disabled. Not sure if that's the case, but would love to hear from FMC/FTD experts on how to solve this issue with minimum impact? is there a CLI command where I can execute from FMC and be done with it(I hope there is)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/140543i6402B1574D5A0155/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 22:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526597#M1086176</guid>
      <dc:creator>Jordan-s</dc:creator>
      <dc:date>2022-01-04T22:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help disabling FTD HA Encryption</title>
      <link>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526729#M1086178</link>
      <description>&lt;P&gt;As you've surmised, "the only way to disable the encryption is by deleting the HA group from FMC GUI and create a new one with encryption disabled".&lt;/P&gt;
&lt;P&gt;There's no cli-based method and it will be a disruptive change. That said, it is otherwise relatively straightforward&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 07:35:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526729#M1086178</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-01-05T07:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Help disabling FTD HA Encryption</title>
      <link>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526880#M1086185</link>
      <description>&lt;P&gt;Thanks for confirming Marvin. I really wish if CISCO adds CLI as an a configuration option to the FTDs, where we can show run, copy the script, modify it and update the configs without the need to touch GUI. Especially if the change involves big FW modifications.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 13:53:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526880#M1086185</guid>
      <dc:creator>Jordan-s</dc:creator>
      <dc:date>2022-01-05T13:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Help disabling FTD HA Encryption</title>
      <link>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526882#M1086186</link>
      <description>&lt;P&gt;For that, "api is the new cli".&lt;/P&gt;
&lt;P&gt;But good luck as a newbie with the API. You will find some good examples online but API capabilities are not yet equal what you can do from FMC (by a long shot).&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 14:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-disabling-ftd-ha-encryption/m-p/4526882#M1086186</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-01-05T14:00:59Z</dc:date>
    </item>
  </channel>
</rss>

